๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2022-36288 โ€ผ

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34648 โ€ผ

Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3670 โ€ผ

MaxQueryDuration not honoured in Samba AD DC LDAP

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2021-3771 โ€ผ

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36282 โ€ผ

Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36347 โ€ผ

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36394 โ€ผ

Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2022-36292 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38663 โ€ผ

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36379 โ€ผ

Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ?Kassa ??? WooCommerce plugin <= 2.3.0 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37113 โ€ผ

Bluecms 1.6 has SQL injection in line 132 of admin/area.php

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36405 โ€ผ

Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37428 โ€ผ

PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38664 โ€ผ

Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36389 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38665 โ€ผ

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36341 โ€ผ

Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS รขโ‚ฌโ€œ Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37112 โ€ผ

BlueCMS 1.6 has SQL injection in line 55 of admin/model.php

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-37111 โ€ผ

BlueCMS 1.6 has SQL injection in line 132 of admin/article.php

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-38172 โ€ผ

ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-1513 โ€ผ

A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.

๐Ÿ“– Read

via "National Vulnerability Database".