🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2021-30063

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

📖 Read

via "National Vulnerability Database".
CVE-2022-1223

Improper Access Control in GitHub repository phpipam/phpipam prior to 1.4.6.

📖 Read

via "National Vulnerability Database".
CVE-2022-1225

Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

📖 Read

via "National Vulnerability Database".
CVE-2022-24191

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

📖 Read

via "National Vulnerability Database".
CVE-2022-1224

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

📖 Read

via "National Vulnerability Database".
CVE-2022-1222

Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

📖 Read

via "National Vulnerability Database".
CVE-2022-0939

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

📖 Read

via "National Vulnerability Database".
🗓️ Cisco software update blocks exploit chain in network management software 🗓️

Patches released for Nexus Dashboard Fabric Controller vulnerabilities

📖 Read

via "The Daily Swig".
🕴 Cybersecurity Mesh: IT's Answer to Cloud Security 🕴

With a properly functioning cybersecurity mesh architecture, one can guarantee safe, authorized access to data from any access point.

📖 Read

via "Dark Reading".
CVE-2022-26616

PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.

📖 Read

via "National Vulnerability Database".
CVE-2021-33616

RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

📖 Read

via "National Vulnerability Database".
CVE-2021-36776

A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

📖 Read

via "National Vulnerability Database".
CVE-2021-44138

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

📖 Read

via "National Vulnerability Database".
CVE-2021-36775

a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

📖 Read

via "National Vulnerability Database".
🗓️ Trezor cryptocurrency wallets targeted with phishing attacks following Mailchimp compromise 🗓️

Company claims false data breach emails were spread via newsletters

📖 Read

via "The Daily Swig".
🤯1
🗓️ Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years 🗓️

PEAR was ripe for exploitation via cryptographic flaw and bug in outdated dependency

📖 Read

via "The Daily Swig".
CVE-2021-43458

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

📖 Read

via "National Vulnerability Database".
CVE-2021-43455

An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

📖 Read

via "National Vulnerability Database".
CVE-2021-43456

An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

📖 Read

via "National Vulnerability Database".
CVE-2022-27435

An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

📖 Read

via "National Vulnerability Database".
CVE-2022-28063

Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.

📖 Read

via "National Vulnerability Database".