βΌ CVE-2022-29585 βΌ
π Read
via "National Vulnerability Database".
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).π Read
via "National Vulnerability Database".
βΌ CVE-2022-22427 βΌ
π Read
via "National Vulnerability Database".
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.π Read
via "National Vulnerability Database".
π΄ Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine π΄
π Read
via "Dark Reading".
Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.π Read
via "Dark Reading".
Dark Reading
Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine
Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.
π The Most Exploited Vulnerabilities of 2021 π
π Read
via "".
U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities say these vulnerabilities were targeted the most by hackers last year.π Read
via "".
Digital Guardian
The Most Exploited Vulnerabilities of 2021
U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities say these vulnerabilities were targeted the most by hackers last year.
π΄ Capital One Ventures, Snowflake Ventures, Verizon Ventures, and Wipro Ventures Join Securonix $1B+ Growth Investment as Strategic Investors π΄
π Read
via "Dark Reading".
Blue Chip Companies Deepen Commitment Based on Success of Long-Standing Customer and Partner Relationships and Conviction of Securonixβs Vision and Hypergrowth Potentialπ Read
via "Dark Reading".
π΄ IT Teams Worry Staff Lack Cloud-Specific Skills π΄
π Read
via "Dark Reading".
Security, cost, and reliability top the list of concerns IT teams have about their cloud operations, according to a recent report.π Read
via "Dark Reading".
Dark Reading
IT Teams Worry Staff Lack Cloud-Specific Skills
Security, cost, and reliability top the list of concerns IT teams have about their cloud operations, according to a recent report.
π΄ Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL π΄
π Read
via "Dark Reading".
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.π Read
via "Dark Reading".
Dark Reading
Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.
βΌ CVE-2022-29555 βΌ
π Read
via "National Vulnerability Database".
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29081 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.π Read
via "National Vulnerability Database".
βΌ CVE-2022-24449 βΌ
π Read
via "National Vulnerability Database".
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28477 βΌ
π Read
via "National Vulnerability Database".
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-28454 βΌ
π Read
via "National Vulnerability Database".
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
βΌ CVE-2022-24898 βΌ
π Read
via "National Vulnerability Database".
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28060 βΌ
π Read
via "National Vulnerability Database".
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29556 βΌ
π Read
via "National Vulnerability Database".
The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29904 βΌ
π Read
via "National Vulnerability Database".
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29907 βΌ
π Read
via "National Vulnerability Database".
The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29905 βΌ
π Read
via "National Vulnerability Database".
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29906 βΌ
π Read
via "National Vulnerability Database".
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29903 βΌ
π Read
via "National Vulnerability Database".
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST request to Special:PrivateDomains.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1531 βΌ
π Read
via "National Vulnerability Database".
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.π Read
via "National Vulnerability Database".