βΌ CVE-2022-36707 βΌ
π Read
via "National Vulnerability Database".
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/bookdetails.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36706 βΌ
π Read
via "National Vulnerability Database".
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36704 βΌ
π Read
via "National Vulnerability Database".
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.π Read
via "National Vulnerability Database".
π΄ Microsoft 365 Empowers Business Users to Shoot Themselves in the Foot π΄
π Read
via "Dark Reading".
Citizen development allows users to design creative solutions for immediate problems, but it requires training and oversight to avoid security holes.π Read
via "Dark Reading".
Dark Reading
Edge Articles
π1
βΌ CVE-2022-38511 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.π Read
via "National Vulnerability Database".
π1
βΌ CVE-2022-36573 βΌ
π Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36615 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36613 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36610 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38510 βΌ
π Read
via "National Vulnerability Database".
Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36614 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36611 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34668 βΌ
π Read
via "National Vulnerability Database".
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36616 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36612 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.π Read
via "National Vulnerability Database".
βΌ CVE-2022-36572 βΌ
π Read
via "National Vulnerability Database".
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.π Read
via "National Vulnerability Database".
π΄ The 3 Questions CISOs Must Ask to Protect Their Sensitive Data π΄
π Read
via "Dark Reading".
CISOs must adopt a new mindset to take on the moving targets in modern cybersecurity.π Read
via "Dark Reading".
Dark Reading
The 3 Questions CISOs Must Ask to Protect Their Sensitive Data
CISOs must adopt a new mindset to take on the moving targets in modern cybersecurity.
βΌ CVE-2022-37059 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Fieldπ Read
via "National Vulnerability Database".
β Tentacles of β0ktapusβ Threat Group Victimize 130 Firms β
π Read
via "Threat Post".
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.π Read
via "Threat Post".
Threat Post
Tentacles of β0ktapusβ Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
π΄ NATO Investigates Dark Web Leak of Data Stolen from Missile Vendor π΄
π Read
via "Dark Reading".
Documents allegedly belonging to an EU defense dealer include those relating to weapons used by Ukraine in its fight against Russia.π Read
via "Dark Reading".
Dark Reading
NATO Investigates Dark Web Leak of Data Stolen From Missile Vendor
Documents allegedly belonging to an EU defense dealer include those relating to weapons used by Ukraine in its fight against Russia.
π΄ Cyber-Insurance Firms Limit Payouts, Risk Obsolescence π΄
π Read
via "Dark Reading".
Businesses need to re-evaluate their cyber-insurance policies as firms like Lloyd's of London continue to add restrictions, including excluding losses related to state-backed cyberattackers.π Read
via "Dark Reading".
Dark Reading
Cyber-Insurance Firms Limit Payouts, Risk Obsolescence
Businesses need to re-evaluate their cyber-insurance policies as firms like Lloyd's of London continue to add restrictions, including excluding losses related to state-backed cyberattackers.