🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-35224 ‼

SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim?s web browser session.

📖 Read

via "National Vulnerability Database".
🕴 PyPI Mandates 2FA, Plans Google Titan Key Giveaway 🕴

Python's most popular package manager is intent on securing the supply chain by requiring developers to enable two-factor authentication.

📖 Read

via "Dark Reading".
‼ CVE-2022-30211 ‼

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-22031 ‼

Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33633 ‼

Skype for Business and Lync Remote Code Execution Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-21845 ‼

Windows Kernel Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30226 ‼

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22022, CVE-2022-22041, CVE-2022-30206.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30216 ‼

Windows Server Service Tampering Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-22047 ‼

Windows CSRSS Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22026, CVE-2022-22049.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-22029 ‼

Windows Network File System Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22039.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30225 ‼

Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33668 ‼

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30181, CVE-2022-33641, CVE-2022-33642, CVE-2022-33643, CVE-2022-33650, CVE-2022-33651, CVE-2022-33652, CVE-2022-33653, CVE-2022-33654, CVE-2022-33655, CVE-2022-33656, CVE-2022-33657, CVE-2022-33658, CVE-2022-33659, CVE-2022-33660, CVE-2022-33661, CVE-2022-33662, CVE-2022-33663, CVE-2022-33664, CVE-2022-33665, CVE-2022-33666, CVE-2022-33667, CVE-2022-33669, CVE-2022-33671, CVE-2022-33672, CVE-2022-33673, CVE-2022-33674, CVE-2022-33675, CVE-2022-33677.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-29600 ‼

The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-22027 ‼

Windows Fax Service Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22024.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30214 ‼

Windows DNS Server Remote Code Execution Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30203 ‼

Windows Boot Manager Security Feature Bypass Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-30187 ‼

Azure Storage Library Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33154 ‼

The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-22041 ‼

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22022, CVE-2022-30206, CVE-2022-30226.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33677 ‼

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30181, CVE-2022-33641, CVE-2022-33642, CVE-2022-33643, CVE-2022-33650, CVE-2022-33651, CVE-2022-33652, CVE-2022-33653, CVE-2022-33654, CVE-2022-33655, CVE-2022-33656, CVE-2022-33657, CVE-2022-33658, CVE-2022-33659, CVE-2022-33660, CVE-2022-33661, CVE-2022-33662, CVE-2022-33663, CVE-2022-33664, CVE-2022-33665, CVE-2022-33666, CVE-2022-33667, CVE-2022-33668, CVE-2022-33669, CVE-2022-33671, CVE-2022-33672, CVE-2022-33673, CVE-2022-33674, CVE-2022-33675.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33673 ‼

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30181, CVE-2022-33641, CVE-2022-33642, CVE-2022-33643, CVE-2022-33650, CVE-2022-33651, CVE-2022-33652, CVE-2022-33653, CVE-2022-33654, CVE-2022-33655, CVE-2022-33656, CVE-2022-33657, CVE-2022-33658, CVE-2022-33659, CVE-2022-33660, CVE-2022-33661, CVE-2022-33662, CVE-2022-33663, CVE-2022-33664, CVE-2022-33665, CVE-2022-33666, CVE-2022-33667, CVE-2022-33668, CVE-2022-33669, CVE-2022-33671, CVE-2022-33672, CVE-2022-33674, CVE-2022-33675, CVE-2022-33677.

📖 Read

via "National Vulnerability Database".