βΌ CVE-2021-46418 βΌ
π Read
via "National Vulnerability Database".
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2021-46419 βΌ
π Read
via "National Vulnerability Database".
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.π Read
via "National Vulnerability Database".
π1
π΄ Keysight Delivers Zero Trust Test Solution π΄
π Read
via "Dark Reading".
Enables network equipment manufacturers to validate devices in distributed cloud networks.π Read
via "Dark Reading".
Dark Reading
Keysight Delivers Zero Trust Test Solution
Enables network equipment manufacturers to validate devices in distributed cloud networks.
π2
ποΈ VMware patches critical flaws in Workspace ONE Access identity management software ποΈ
π Read
via "The Daily Swig".
Virtual realityπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
VMware patches critical flaws in Workspace ONE Access identity management software
Virtual reality
π΄ Nord Security Raises First Outside Capital at $1.6B Valuation π΄
π Read
via "Dark Reading".
Financing raised from Novator Ventures, Burda Principal Investments, General Catalyst, and leading angel investors.π Read
via "Dark Reading".
Dark Reading
Nord Security Raises First Outside Capital at $1.6B Valuation
Financing raised from Novator Ventures, Burda Principal Investments, General Catalyst, and leading angel investors.
βΌ CVE-2022-27016 βΌ
π Read
via "National Vulnerability Database".
There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25339 βΌ
π Read
via "National Vulnerability Database".
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25338 βΌ
π Read
via "National Vulnerability Database".
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26627 βΌ
π Read
via "National Vulnerability Database".
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.π Read
via "National Vulnerability Database".
π΄ Top Application Security Mitigations in Q1 of 2022 π΄
π Read
via "Dark Reading".
What is the best way to mitigate application security attacks? Learn how companies have mitigated the top threats.π Read
via "Dark Reading".
Dark Reading
Top Application Security Mitigations in Q1 of 2022
What is the best way to mitigate application security attacks? Learn how companies have mitigated the top threats.
βΌ CVE-2022-23972 βΌ
π Read
via "National Vulnerability Database".
ASUS RT-AX56UΓ’β¬β’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22515 βΌ
π Read
via "National Vulnerability Database".
A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22519 βΌ
π Read
via "National Vulnerability Database".
A remote, authenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver and the CODESYS Control runtime system.π Read
via "National Vulnerability Database".
βΌ CVE-2022-26671 βΌ
π Read
via "National Vulnerability Database".
Taiwan Secom Dr.ID Access Control systemΓ’β¬β’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.π Read
via "National Vulnerability Database".
βΌ CVE-2022-0677 βΌ
π Read
via "National Vulnerability Database".
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.π Read
via "National Vulnerability Database".
βΌ CVE-2022-22514 βΌ
π Read
via "National Vulnerability Database".
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. This causes a null pointer dereference in the CmpSettings component of the affected CODESYS products and leads to a crash.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25595 βΌ
π Read
via "National Vulnerability Database".
ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43432 βΌ
π Read
via "National Vulnerability Database".
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25594 βΌ
π Read
via "National Vulnerability Database".
MicroprogramΓ’β¬β’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs to acquire partial system configuration information.π Read
via "National Vulnerability Database".
π2
βΌ CVE-2022-22517 βΌ
π Read
via "National Vulnerability Database".
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.π Read
via "National Vulnerability Database".
βΌ CVE-2022-25597 βΌ
π Read
via "National Vulnerability Database".
ASUS RT-AC86UΓ’β¬β’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.π Read
via "National Vulnerability Database".