πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-29733 β€Ό

Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1968 β€Ό

Use After Free in GitHub repository vim/vim prior to 8.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29734 β€Ό

A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24240 β€Ό

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30797 β€Ό

Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31957 β€Ό

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30832 β€Ό

Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30798 β€Ό

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31796 β€Ό

libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43306 β€Ό

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31350 β€Ό

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23236 β€Ό

E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-42203 β€Ό

An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32004 β€Ό

Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29648 β€Ό

A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30808 β€Ό

elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30277 β€Ό

BD SynapsysΓ’β€žΒ’, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30115 β€Ό

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-29483 β€Ό

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31336 β€Ό

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-12350 β€Ό

An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

πŸ“– Read

via "National Vulnerability Database".