βΌ CVE-2023-24146 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24145 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.π Read
via "National Vulnerability Database".
π΄ Scores of Redis Servers Infested by Sophisticated Custom-Built Malware π΄
π Read
via "Dark Reading".
At least 1,200 Redis servers worldwide have been infected with "HeadCrab" cryptominers since 2021.π Read
via "Dark Reading".
Dark Reading
Scores of Redis Servers Infested by Sophisticated Custom-Built Malware
At least 1,200 Redis servers worldwide have been infected with "HeadCrab" cryptominers since 2021.
β S3 Ep120: When dud crypto simply wonβt let go [Audio + Text] β
π Read
via "Naked Security".
Latest episode - listen now!π Read
via "Naked Security".
Naked Security
S3 Ep120: When dud crypto simply wonβt let go [Audio + Text]
Latest episode β listen now!
β OpenSSH fixes double-free memory bug thatβs pokable over the network β
π Read
via "Naked Security".
It's a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct code...π Read
via "Naked Security".
Naked Security
OpenSSH fixes double-free memory bug thatβs pokable over the network
Itβs a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct codeβ¦
βΌ CVE-2021-36431 βΌ
π Read
via "National Vulnerability Database".
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36532 βΌ
π Read
via "National Vulnerability Database".
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37377 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36544 βΌ
π Read
via "National Vulnerability Database".
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37234 βΌ
π Read
via "National Vulnerability Database".
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37376 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37304 βΌ
π Read
via "National Vulnerability Database".
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36569 βΌ
π Read
via "National Vulnerability Database".
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36712 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36535 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37501 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37379 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37305 βΌ
π Read
via "National Vulnerability Database".
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37316 βΌ
π Read
via "National Vulnerability Database".
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37375 βΌ
π Read
via "National Vulnerability Database".
** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.π Read
via "National Vulnerability Database".
βΌ CVE-2021-36493 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.π Read
via "National Vulnerability Database".