‼ CVE-2022-30411 ‼
📖 Read
via "National Vulnerability Database".
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-28830 ‼
📖 Read
via "National Vulnerability Database".
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30399 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30395 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30375 ‼
📖 Read
via "National Vulnerability Database".
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30403 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29792 ‼
📖 Read
via "National Vulnerability Database".
The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30402 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30392 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30401 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30379 ‼
📖 Read
via "National Vulnerability Database".
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29791 ‼
📖 Read
via "National Vulnerability Database".
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29854 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30391 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30376 ‼
📖 Read
via "National Vulnerability Database".
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30396 ‼
📖 Read
via "National Vulnerability Database".
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30415 ‼
📖 Read
via "National Vulnerability Database".
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.📖 Read
via "National Vulnerability Database".
🛠 COOPER Analysis Tool 🛠
📖 Read
via "Packet Storm Security".
Cooper utilizes cooperative mutation to test the binding code of scripting languages to find memory-safe issues. Cooperative mutation simultaneously modifies the script code and the related document objects to explore various code paths of the binding code. To support cooperative mutation, the authors infer the relationship between script code and document objects to guide the two-dimensional mutation. They applied their tool Cooper on three popular commercial PDF tools, Adobe Acrobat, Foxit Reader, and Microsoft Word. Cooper detected 134 previously unknown bugs, which resulted in 33 CVE entries and 22K bug bounties.📖 Read
via "Packet Storm Security".
Packetstormsecurity
COOPER Analysis Tool ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
🕴 Linux, OpenSSF Champion Plan to Improve Open Source Security 🕴
📖 Read
via "Dark Reading".
The White House and tech industry pledge $150 million over two years to boost open source resiliency and supply chain security.📖 Read
via "Dark Reading".
Dark Reading
Linux, OpenSSF Champion Plan to Improve Open Source Security
The White House and tech industry pledge $150 million over two years to boost open source resiliency and supply chain security.
🔏 Friday Five 5/13 🔏
📖 Read
via "".
Data privacy concerns on the rise, Costa Rica fights back against ransomware, and new cybersecurity legislation making its way through Congress - read about this and more in this week's Friday Five!
📖 Read
via "".
Digital Guardian
Friday Five 5/13
Data privacy concerns on the rise, Costa Rica fights back against ransomware, and new cybersecurity legislation making its way through Congress - read about this and more in this week's Friday Five!
‼ CVE-2022-1715 ‼
📖 Read
via "National Vulnerability Database".
Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.📖 Read
via "National Vulnerability Database".