🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
‼ CVE-2022-25735 ‼

Denial of service in modem due to missing null check while processing TCP or UDP packets from server

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44448 ‼

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47358 ‼

In log service, there is a missing permission check. This could lead to local denial of service in log service.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-25734 ‼

Denial of service in modem due to missing null check while processing IP packets with padding

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47347 ‼

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47364 ‼

In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47341 ‼

In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-45090 ‼

Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-45086 ‼

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS).This issue affects Smartpower Web: before 23.01.01.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-38686 ‼

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-44447 ‼

In wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of service in wlan services.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-33216 ‼

Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file.

📖 Read

via "National Vulnerability Database".
‼ CVE-2022-47332 ‼

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0784 ‼

A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220644.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0785 ‼

A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220645 was assigned to this vulnerability.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0787 ‼

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0794 ‼

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0786 ‼

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0790 ‼

Uncaught Exception in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0792 ‼

Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".
‼ CVE-2023-0789 ‼

Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

📖 Read

via "National Vulnerability Database".