βΌ CVE-2022-29728 βΌ
π Read
via "National Vulnerability Database".
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29318 βΌ
π Read
via "National Vulnerability Database".
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29655 βΌ
π Read
via "National Vulnerability Database".
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29656 βΌ
π Read
via "National Vulnerability Database".
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29975 βΌ
π Read
via "National Vulnerability Database".
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .π Read
via "National Vulnerability Database".
βΌ CVE-2020-19228 βΌ
π Read
via "National Vulnerability Database".
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29976 βΌ
π Read
via "National Vulnerability Database".
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .π Read
via "National Vulnerability Database".
βΌ CVE-2022-29317 βΌ
π Read
via "National Vulnerability Database".
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.π Read
via "National Vulnerability Database".
π΄ SpyCloud Report: Fortune 1000 Employees Pose Elevated Cyber Risk to Companies π΄
π Read
via "Dark Reading".
Analysis finds 687 million exposed credentials and personally identifiable information (PII) among Fortune 1000 employees, and a 64% password reuse rate.π Read
via "Dark Reading".
Darkreading
SpyCloud Report: Fortune 1000 Employees Pose Elevated Cyber Risk to Companies
Analysis finds 687 million exposed credentials and personally identifiable information (PII) among Fortune 1000 employees, and a 64% password reuse rate.
ποΈ CyberUK 2022: Global power conflicts creating βbalkinizationβ of cybersecurity tech ποΈ
π Read
via "The Daily Swig".
Technology interoperability at risk from wider conflict between China and the Westπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
CyberUK 2022: Global power conflicts creating βbalkinizationβ of cybersecurity tech
Technology interoperability at risk from wider conflict between China and the West
βΌ CVE-2021-44167 βΌ
π Read
via "National Vulnerability Database".
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-27656 βΌ
π Read
via "National Vulnerability Database".
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-1622 βΌ
π Read
via "National Vulnerability Database".
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28214 βΌ
π Read
via "National Vulnerability Database".
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systemsΓ’β¬β’ Confidentiality, Integrity, and Availability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29977 βΌ
π Read
via "National Vulnerability Database".
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28774 βΌ
π Read
via "National Vulnerability Database".
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29898 βΌ
π Read
via "National Vulnerability Database".
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29009 βΌ
π Read
via "National Vulnerability Database".
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29610 βΌ
π Read
via "National Vulnerability Database".
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.π Read
via "National Vulnerability Database".
βΌ CVE-2022-28077 βΌ
π Read
via "National Vulnerability Database".
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2022-29008 βΌ
π Read
via "National Vulnerability Database".
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.π Read
via "National Vulnerability Database".