πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-37426 β€Ό

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43168 β€Ό

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37424 β€Ό

Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3400 β€Ό

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43165 β€Ό

A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Value parameter after clicking "Create".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38217 β€Ό

SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43167 β€Ό

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43164 β€Ό

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38729 β€Ό

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38733 β€Ό

SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-38728 β€Ό

SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36858 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43229 (simple_cold_storage_managment_system) β€Ό

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2474 β€Ό

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the Ò€œEthernet Q CommandsҀ� service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41648 β€Ό

The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the HARTFORD 5A-65E CNC machine is vulnerable to improper authentication, which may allow an attacker to deny service to the production line, steal sensitive data from the production line, and alter any products created by the production line.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36864 β€Ό

Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43230 (simple_cold_storage_managment_system) β€Ό

Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-2475 β€Ό

Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3402 β€Ό

The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing an action like clicking on a link, or an authenticated user with access to a page that sends a request using user-supplied data via the server, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-36898 β€Ό

Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3708 β€Ό

The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This made it possible for authenticated users to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

πŸ“– Read

via "National Vulnerability Database".