βΌ CVE-2023-1262 βΌ
π Read
via "National Vulnerability Database".
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1532 βΌ
π Read
via "National Vulnerability Database".
Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)π Read
via "National Vulnerability Database".
βΌ CVE-2023-1534 βΌ
π Read
via "National Vulnerability Database".
Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)π Read
via "National Vulnerability Database".
π’ What is 'steal now, crack later'? π’
π Read
via "ITPro".
The rise in quantum computing this decade is pushing cyber criminals into stealing encrypted business data with the hopes of cracking it in the futureπ Read
via "ITPro".
ITPro
What is the βsteal now, crack laterβ quantum computing threat?
The rise in quantum computing this decade is pushing cyber criminals into stealing encrypted business data with the hopes of cracking it in the future
π’ NCSC launches free in-browser security threat checks for SMBs π’
π Read
via "ITPro".
The new cyber toolkits will help SMBs assess their cyber readiness in a matter of minutesπ Read
via "ITPro".
ITPro
NCSC launches free in-browser security threat checks for SMBs
The new cyber toolkits will help SMBs assess their cyber readiness in a matter of minutes
π€1
π’ Greek intelligence allegedly uses Predator spyware on Facebook staffer π’
π Read
via "ITPro".
The employeeβs device was infected through a link pretending to confirm a vaccination appointmentπ Read
via "ITPro".
ITPro
Greek intelligence allegedly uses Predator spyware to wiretap Facebook security staffer
The employeeβs device was infected through a link pretending to confirm a vaccination appointment
β€1
βΌ CVE-2023-27855 βΌ
π Read
via "National Vulnerability Database".
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27857 βΌ
π Read
via "National Vulnerability Database".
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28725 βΌ
π Read
via "National Vulnerability Database".
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45634 βΌ
π Read
via "National Vulnerability Database".
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive account informationπ Read
via "National Vulnerability Database".
βΌ CVE-2023-27856 βΌ
π Read
via "National Vulnerability Database".
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.π Read
via "National Vulnerability Database".
βΌ CVE-2022-37940 βΌ
π Read
via "National Vulnerability Database".
Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28005 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows? Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker must first obtain physical access to the target system in order to exploit this vulnerability. It is also important to note that the contents of the drive(s) encrypted with TMEE FDE would still be protected and would NOT be accessible by the attacker by exploitation of this vulnerability alone.π Read
via "National Vulnerability Database".
π₯1
βΌ CVE-2023-1558 βΌ
π Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223551.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1556 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Judging Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file summary_results.php. The manipulation of the argument main_event_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223549 was assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1557 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ecommerce/admin/user/controller.php?action=edit of the component Username Handler. The manipulation of the argument USERID leads to improper access controls. The attack may be launched remotely. VDB-223550 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28708 βΌ
π Read
via "National Vulnerability Database".
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1562 βΌ
π Read
via "National Vulnerability Database".
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1572 βΌ
π Read
via "National Vulnerability Database".
A vulnerability has been found in DataGear up to 1.11.1 and classified as problematic. This vulnerability affects unknown code of the component Plugin Handler. The manipulation leads to cross site scripting. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 1.12.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-223564.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1563 βΌ
π Read
via "National Vulnerability Database".
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/assign/assign.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223555.π Read
via "National Vulnerability Database".
βΌ CVE-2023-1565 βΌ
π Read
via "National Vulnerability Database".
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223557 was assigned to this vulnerability.π Read
via "National Vulnerability Database".