βΌ CVE-2022-44139 βΌ
π Read
via "National Vulnerability Database".
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44256 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44253 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44280 βΌ
π Read
via "National Vulnerability Database".
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44258 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44252 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44259 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44249 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44254 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44255 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.π Read
via "National Vulnerability Database".
βΌ CVE-2022-44257 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.π Read
via "National Vulnerability Database".
π΄ Microsoft: Popular IoT SDKs Leave Critical Infrastructure Wide Open to Cyberattack π΄
π Read
via "Dark Reading".
Chinese threat actors have already used the vulnerable and pervasive Boa server to infiltrate the electrical grid in India, in spate of malicious incidents.π Read
via "Dark Reading".
Dark Reading
Microsoft: Popular IoT SDKs Leave Critical Infrastructure Wide Open to Cyberattack
Chinese threat actors have already used the vulnerable and pervasive Boa server to infiltrate the electrical grid in India, in spate of malicious incidents.
π΄ Hot Ticket: 'Aurora' Go-Based InfoStealer Finds Favor Among Cyber-Threat Actors π΄
π Read
via "Dark Reading".
The infostealer Auroraβs low detection rates and newcomer status are helping it fly under the radar, as more cybercriminal gangs target cryptocurrency wallets and communications apps.π Read
via "Dark Reading".
Dark Reading
Hot Ticket: 'Aurora' Go-Based InfoStealer Finds Favor Among Cyber-Threat Actors
The infostealer Auroraβs low detection rates and newcomer status are helping it fly under the radar, as more cybercriminal gangs target cryptocurrency wallets and communications apps.
π΄ 'Patch Lag' Leaves Millions of Android Devices Vulnerable π΄
π Read
via "Dark Reading".
Months after a fix was issued by a vendor, downstream Android device manufacturers still haven't patched, highlighting a troubling trend.π Read
via "Dark Reading".
Dark Reading
'Patch Lag' Leaves Millions of Android Devices Vulnerable
Months after a fix was issued by a vendor, downstream Android device manufacturers still haven't patched, highlighting a troubling trend.
β CryptoRom βpig butcheringβ scam sites seized, suspects arrested in US β
π Read
via "Naked Security".
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...π Read
via "Naked Security".
Naked Security
Multimillion dollar CryptoRom scam sites seized, suspects arrested in US
Five tips to keep yourself, and your friends and family, out of the clutches of βchopping blockβ scammersβ¦
βΌ CVE-2021-35284 βΌ
π Read
via "National Vulnerability Database".
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.π Read
via "National Vulnerability Database".
βΌ CVE-2022-41922 βΌ
π Read
via "National Vulnerability Database".
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.π Read
via "National Vulnerability Database".
βΌ CVE-2022-23740 βΌ
π Read
via "National Vulnerability Database".
CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub Actions. This vulnerability affected only version 3.7.0 of GitHub Enterprise Server and was fixed in version 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40772 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.π Read
via "National Vulnerability Database".
βΌ CVE-2022-40304 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38113 βΌ
π Read
via "National Vulnerability Database".
This vulnerability discloses build and services versions in the server response header.π Read
via "National Vulnerability Database".