🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🗓️ Cisco software update blocks exploit chain in network management software 🗓️

Patches released for Nexus Dashboard Fabric Controller vulnerabilities

📖 Read

via "The Daily Swig".
🕴 Cybersecurity Mesh: IT's Answer to Cloud Security 🕴

With a properly functioning cybersecurity mesh architecture, one can guarantee safe, authorized access to data from any access point.

📖 Read

via "Dark Reading".
CVE-2022-26616

PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.

📖 Read

via "National Vulnerability Database".
CVE-2021-33616

RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.

📖 Read

via "National Vulnerability Database".
CVE-2021-36776

A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

📖 Read

via "National Vulnerability Database".
CVE-2021-44138

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

📖 Read

via "National Vulnerability Database".
CVE-2021-36775

a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

📖 Read

via "National Vulnerability Database".
🗓️ Trezor cryptocurrency wallets targeted with phishing attacks following Mailchimp compromise 🗓️

Company claims false data breach emails were spread via newsletters

📖 Read

via "The Daily Swig".
🤯1
🗓️ Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years 🗓️

PEAR was ripe for exploitation via cryptographic flaw and bug in outdated dependency

📖 Read

via "The Daily Swig".
CVE-2021-43458

An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

📖 Read

via "National Vulnerability Database".
CVE-2021-43455

An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

📖 Read

via "National Vulnerability Database".
CVE-2021-43456

An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

📖 Read

via "National Vulnerability Database".
CVE-2022-27435

An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

📖 Read

via "National Vulnerability Database".
CVE-2022-28063

Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.

📖 Read

via "National Vulnerability Database".
CVE-2022-27436

A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.

📖 Read

via "National Vulnerability Database".
CVE-2021-43457

An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

📖 Read

via "National Vulnerability Database".
CVE-2022-1026

Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

📖 Read

via "National Vulnerability Database".
CVE-2022-28062

Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.

📖 Read

via "National Vulnerability Database".
CVE-2021-43454

An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

📖 Read

via "National Vulnerability Database".
CVE-2022-24787

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty nonzero bytes, two bytestrings can compare to equal if one ends with `"\x00"` because there is no comparison of the length. A patch is available and expected to be part of the 0.3.2 release. There are currently no known workarounds.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2022-0990

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

📖 Read

via "National Vulnerability Database".