πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-3277 β€Ό

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4134 β€Ό

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27891 β€Ό

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3854 β€Ό

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20251 β€Ό

A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3424 β€Ό

A use-after-free flaw was found in the Linux kernelÒ€ℒs SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1240 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1239 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1242 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3760 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med.This issue affects Mia-Med: before 1.0.0.58.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1243 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1238 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1247 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 11.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1244 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1237 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1241 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1245 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cyber Security Works to Rebrand As Securin Inc. πŸ•΄

Securin Inc. will provide tech-enabled security solutions, vulnerability intelligence and deep domain expertise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware's Favorite Target: Critical Infrastructure and Its Industrial Control Systems πŸ•΄

The health, manufacturing, and energy sectors are the most vulnerable to ransomware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26955 β€Ό

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.

πŸ“– Read

via "National Vulnerability Database".