πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-22704 β€Ό

Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Just 1% of Nonprofit Domains Have Basic DMARC Email Security Protections πŸ•΄

DMARC blocks spam and phishing emails sent from spoofed domains, and it's vastly underutilized, a new report says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-28422 β€Ό

Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4224 β€Ό

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Okta Post-Exploitation Method Exposes User Passwords πŸ•΄

Accidentally typing a password in the username field of the platform saves them to audit logs, to which threat actors can gain access and use to compromise enterprise services.

πŸ“– Read

via "Dark Reading".
⚠ Windows 11 also vulnerable to β€œaCropalypse” image data leakage ⚠

Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-23728 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Flipclock plugin <= 1.7.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28491 β€Ό

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27079 β€Ό

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23864 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28492 β€Ό

TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23722 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP eBay Product Feeds plugin <= 3.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22712 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext ToolKit plugin <= 3.2.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22716 β€Ό

Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27078 β€Ό

A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27077 β€Ό

Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22702 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App Ò€” Android and iOS Mobile Application plugin <= 11.13 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47589 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28493 β€Ό

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28772 β€Ό

An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27135 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.

πŸ“– Read

via "National Vulnerability Database".