πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-40832 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3422 β€Ό

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40829 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40835 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3423 β€Ό

Denial of Service in GitHub repository nocodb/nocodb prior to 0.92.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40828 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40830 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40825 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40827 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40834 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40872 β€Ό

An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40831 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40833 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40826 β€Ό

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function.

πŸ“– Read

via "National Vulnerability Database".
πŸ—“οΈ Policy-as-code approach counters β€˜cloud native’ security risks πŸ—“οΈ

Research suggests that automation can cut down on cloud control plane compromises

πŸ“– Read

via "The Daily Swig".
πŸ” Friday Five 10/7 πŸ”

This week saw some good news around securing the midterm elections, warnings about IRS phishing scams, and new orders from CISA. Catch up in this week’s Friday Five!


πŸ“– Read

via "".
β€Ό CVE-2022-39847 β€Ό

Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-33896 β€Ό

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39852 β€Ό

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39863 β€Ό

Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39867 β€Ό

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.

πŸ“– Read

via "National Vulnerability Database".