πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27135 β€Ό

xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28506 β€Ό

There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27428 β€Ό

A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the album_name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28586 β€Ό

XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27103 β€Ό

element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27429 β€Ό

Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27311 β€Ό

Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36460 β€Ό

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28053 β€Ό

Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Trend Micro Launches New Security Platform πŸ•΄

An ecosystem of native and third-party integrations provides visibility and control across the entire attack surface.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ IBM database updates address critical vulnerabilities in third-party XML parser πŸ—“οΈ

Flaws in popular parser prompt updates from numerous downstream vendors

πŸ“– Read

via "The Daily Swig".
πŸ‘1
⚠ QNAP warns of new bugs in its Network Attached Storage devices ⚠

Here's what you need to know - plus some sensible advice for all the devices on your home or small biz network!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-28093 β€Ό

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29078 β€Ό

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28094 β€Ό

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26111 β€Ό

The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.

πŸ“– Read

via "National Vulnerability Database".
⚠ Phishing goes KISS: Don’t let plain and simple messages catch you out! ⚠

Sometimes we receive phishing tricks that we grudgingly have to admit are better than average, just because they're uncomplicated.

πŸ“– Read

via "Naked Security".
πŸ•΄ Ukraine Invasion Driving DDoS Attacks to All-Time Highs πŸ•΄

Unprecedented numbers of DDoS attacks since February are the result of hacktivists' cyberwar against Russian state interests, researchers say.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-0953 β€Ό

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0398 β€Ό

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26597 β€Ό

Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.

πŸ“– Read

via "National Vulnerability Database".