πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-24670 β€Ό

An attacker can use the unrestricted LDAP queries to determine configuration entries

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41996 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3725 β€Ό

Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3095 β€Ό

The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to auth bypass in webapps interpreting URIs. We recommend updating Dart or Flutter to mitigate the issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40183 β€Ό

An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24669 β€Ό

It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39978 β€Ό

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0072 β€Ό

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server Dashboard allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41555 β€Ό

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3385 β€Ό

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41773 β€Ό

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41701 β€Ό

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0074 β€Ό

Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43340 β€Ό

A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41627 β€Ό

The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphoneÒ€ℒs ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3386 β€Ό

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41133 β€Ό

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39976 β€Ό

School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40876 β€Ό

In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39977 β€Ό

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40965 β€Ό

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

πŸ“– Read

via "National Vulnerability Database".