πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-25997 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26027 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25957 β€Ό

This candidate was in a CNA pool that was not assigned to any issues during 2022.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0089 β€Ό

The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0090 β€Ό

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24657 β€Ό

phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23638 β€Ό

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1267 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart.This issue affects PtteM Kart: before 2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1269 β€Ό

Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Tech Giants Go Cloud-Native Shopping πŸ•΄

Cisco’s acquisition of cloud-native firewall provider Valtix and HPE’s deal to buy SSE provider Axis Security fill gaps in their existing portfolios.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Rising Public Cloud Adoption Is Accelerating Shadow Data Risks πŸ•΄

Using a risk-based approach to deal with policy violations and continuous compliance monitoring will help avoid data exposures and fines.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-25395 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 router has a command injection vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26950 β€Ό

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1270 β€Ό

Command Injection in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26952 β€Ό

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Lacework Launches Secured by Women Initiative πŸ•΄

For International Women's Month, new ongoing initiative is aimed at celebrating women and bringing visibility to those making cybersecurity history.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Surge in Cloud Adoption Means a Greater Data Attack Surface for Healthcare and Financial Services πŸ•΄

Organizations in both industries are falling short when addressing new challenges to protect data in the cloud, finds Blancco report.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-24773 β€Ό

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26922 β€Ό

SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26261 β€Ό

In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27088 β€Ό

feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will.

πŸ“– Read

via "National Vulnerability Database".