πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28111 β€Ό

MyBatis PageHelper v1.x.x-v5.x.x was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28096 β€Ό

Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks πŸ—“οΈ

Unpatched flaw caused by the predictability of transaction IDs

πŸ“– Read

via "The Daily Swig".
⚠ Firefox hits 100*, fixes bugs… but no new zero-days this month ⚠

Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

πŸ“– Read

via "Naked Security".
πŸ•΄ AI for Cybersecurity Shimmers With Promise, But Challenges Abound πŸ•΄

Companies see AI-powered cybersecurity tools and systems as the future, but at present nearly 90% of them say they face significant hurdles in making use of them.

πŸ“– Read

via "Dark Reading".
⚠ Android monthly updates are out – critical bugs found in critical places! ⚠

Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-29347 β€Ό

An arbitrary file upload vulnerability in Web@archiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28552 β€Ό

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28081 β€Ό

A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27903 β€Ό

An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25784 β€Ό

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28512 β€Ό

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28076 β€Ό

Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28487 β€Ό

Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25787 β€Ό

Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28066 β€Ό

Libarchive v3.6.0 was discovered to contain a read memory access vulnerability via the function lzma_decode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25785 β€Ό

Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code execution. This issue affects: Secomea SiteManager all versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25781 β€Ό

Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28067 β€Ό

An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28488 β€Ό

The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25783 β€Ό

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

πŸ“– Read

via "National Vulnerability Database".