πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-48085 β€Ό

Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-0679 β€Ό

A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file removeUser.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220220.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48164 β€Ό

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-45722 β€Ό

ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
⚠ Finnish psychotherapy extortion suspect arrested in France ⚠

Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Google engineers plot to mitigate prototype pollution πŸ—“οΈ

Plan to create boundary between JavaScript objects and their blueprints gathers momentum

πŸ“– Read

via "The Daily Swig".
πŸ›  GNUnet P2P Framework 0.19.3 πŸ› 

GNUnet is a peer-to-peer framework with focus on providing security. All peer-to-peer messages in the network are confidential and authenticated. The framework provides a transport abstraction layer and can currently encapsulate the network traffic in UDP (IPv4 and IPv6), TCP (IPv4 and IPv6), HTTP, or SMTP messages. GNUnet supports accounting to provide contributing nodes with better service. The primary service build on top of the framework is anonymous file sharing.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2023-24200 β€Ό

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24192 β€Ό

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48078 β€Ό

pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24198 β€Ό

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24197 β€Ό

Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24202 β€Ό

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24194 β€Ό

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-24195 β€Ό

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24191 β€Ό

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24276 β€Ό

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24201 β€Ό

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24199 β€Ό

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48019 β€Ό

The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege escalation via a crafted payload.

πŸ“– Read

via "National Vulnerability Database".
⚠ Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto ⚠

Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...

πŸ“– Read

via "Naked Security".