πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-1511 β€Ό

Improper Access Control in GitHub repository snipe/snipe-it prior to 5.4.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24892 β€Ό

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28117 β€Ό

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22443 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29411 β€Ό

SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29412 β€Ό

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit ????? plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29584 β€Ό

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22322 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29415 β€Ό

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28892 β€Ό

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1514 β€Ό

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22441 β€Ό

IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29413 β€Ό

Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress via &title parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29410 β€Ό

Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38952 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27860 β€Ό

Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29585 β€Ό

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22427 β€Ό

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine πŸ•΄

Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.

πŸ“– Read

via "Dark Reading".
πŸ” The Most Exploited Vulnerabilities of 2021 πŸ”

U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities say these vulnerabilities were targeted the most by hackers last year.

πŸ“– Read

via "".
πŸ•΄ Capital One Ventures, Snowflake Ventures, Verizon Ventures, and Wipro Ventures Join Securonix $1B+ Growth Investment as Strategic Investors πŸ•΄

Blue Chip Companies Deepen Commitment Based on Success of Long-Standing Customer and Partner Relationships and Conviction of Securonix’s Vision and Hypergrowth Potential

πŸ“– Read

via "Dark Reading".