πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-27891 β€Ό

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3854 β€Ό

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-20251 β€Ό

A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3424 β€Ό

A use-after-free flaw was found in the Linux kernelÒ€ℒs SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1240 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1239 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1242 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-3760 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med.This issue affects Mia-Med: before 1.0.0.58.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1243 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1238 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1247 β€Ό

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 11.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1244 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1237 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1241 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1245 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cyber Security Works to Rebrand As Securin Inc. πŸ•΄

Securin Inc. will provide tech-enabled security solutions, vulnerability intelligence and deep domain expertise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Ransomware's Favorite Target: Critical Infrastructure and Its Industrial Control Systems πŸ•΄

The health, manufacturing, and energy sectors are the most vulnerable to ransomware.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26955 β€Ό

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-36669 β€Ό

The JetBackup Γ’β‚¬β€œ WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9. This is due to missing nonce validation on the backup_guard_get_import_backup() function. This makes it possible for unauthenticated attackers to upload arbitrary files to the vulnerable site's server via a forged request, granted they can trick a site's administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44197 β€Ό

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System.This issue affects Student Information Management System: before 20211126.

πŸ“– Read

via "National Vulnerability Database".