πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-30489 β€Ό

WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30373 β€Ό

Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast] ⚠

Latest episode - lots to learn - plain English - fun with a serious side - listen now!

πŸ“– Read

via "Naked Security".
⚠ Serious Security: Learning from curl’s latest bug update ⚠

Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.

πŸ“– Read

via "Naked Security".
⚠ He cracked passwords for a living – now he’s serving 4 years in prison ⚠

Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

πŸ“– Read

via "Naked Security".
πŸ•΄ Log4Shell Exploit Threatens Enterprise Data Lakes, AI Poisoning πŸ•΄

A brand-new attack vector lays open enterprise data lakes, threatening grave consequences for AI use cases like telesurgery or autonomous cars.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Black Hat Asia: β€˜If democracy is to survive, technology will have to be tamed’ πŸ—“οΈ

Indian tech policy expert Samir Saran says it’s not too late to β€˜course-correct’ after a β€˜challenging decade’ for liberal democracies

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-28827 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29790 β€Ό

The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28826 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29794 β€Ό

The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30386 β€Ό

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28822 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46785 β€Ό

The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30417 β€Ό

Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22261 β€Ό

The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30381 β€Ό

Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30384 β€Ό

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28821 β€Ό

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30398 β€Ό

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30412 β€Ό

Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.

πŸ“– Read

via "National Vulnerability Database".