πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25968 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23224 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2021.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26416 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-23232 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2021.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26123 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26055 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26031 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26418 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25997 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26027 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25957 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0089 β€Ό

The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0090 β€Ό

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24657 β€Ό

phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23638 β€Ό

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1267 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart.This issue affects PtteM Kart: before 2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1269 β€Ό

Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Tech Giants Go Cloud-Native Shopping πŸ•΄

Cisco’s acquisition of cloud-native firewall provider Valtix and HPE’s deal to buy SSE provider Axis Security fill gaps in their existing portfolios.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Rising Public Cloud Adoption Is Accelerating Shadow Data Risks πŸ•΄

Using a risk-based approach to deal with policy violations and continuous compliance monitoring will help avoid data exposures and fines.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-25395 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 router has a command injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26950 β€Ό

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.

πŸ“– Read

via "National Vulnerability Database".