πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Protecting Hospital Networks From 'Code Dark' Scenarios πŸ•΄

Asset inventory, behavioral baselining, and automated response are all key to keeping patients healthy and safe.  

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-45942 β€Ό

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46534 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46549 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/saveParentControlInfo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46531 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/addWifiMacFilter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46544 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the cmdinput parameter at /goform/exeCommand.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-40624 β€Ό

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46550 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46546 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/RouteStatic.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46540 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/addressNat.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45666 β€Ό

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46532 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46533 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46542 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/addressNat.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46545 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45665 β€Ό

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46547 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46538 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-46548 β€Ό

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/DhcpListClient.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-44643 β€Ό

In Grafana Enterprise Metrics (GEM) before 1.7.1 and 2.x before 2.3.1, after creating an Access Policy that is granted access to all tenants as well as specified a specific label matcher, the label matcher is erroneously not propagated to queries performed with this access policy. Thus, more access is granted to the policy than intended.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4619 β€Ό

The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Γ’β‚¬ΛœExtra CSS classÒ€ℒ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

πŸ“– Read

via "National Vulnerability Database".