πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40322 β€Ό

SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40324 β€Ό

SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37794 β€Ό

In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36254 β€Ό

Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37796 β€Ό

In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36257 β€Ό

A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36259 β€Ό

A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "username", "password", etc.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36258 β€Ό

A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36255 β€Ό

A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34109 β€Ό

An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38972 β€Ό

Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34110 β€Ό

An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-34108 β€Ό

An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36256 β€Ό

A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ WordPress project WPHash harvests 75 million hashes for detecting vulnerable plugins πŸ—“οΈ

Project mission is to crowdsource the indexing and curating of plugin bug data

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Vulnerability in Xalan-J could allow arbitrary code execution πŸ—“οΈ

Open source project is used by various SAML implementations

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2022-37767 β€Ό

Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37734 β€Ό

graphql-java before19.0 is vulnerable to Denial of Service. An attacker send a malicious GraphQL query that consumes CPU resources.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37797 β€Ό

In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

πŸ“– Read

via "National Vulnerability Database".
⚠ How to deal with dates and times without any timezone tantrums… ⚠

Heartfelt encouragement to embrace RFC 3339 - find out why!

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-3178 β€Ό

Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.

πŸ“– Read

via "National Vulnerability Database".