πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-28491 β€Ό

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27079 β€Ό

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23864 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28492 β€Ό

TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23722 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP eBay Product Feeds plugin <= 3.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22712 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext ToolKit plugin <= 3.2.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22716 β€Ό

Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27078 β€Ό

A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27077 β€Ό

Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22702 β€Ό

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App Ò€” Android and iOS Mobile Application plugin <= 11.13 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47589 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-28493 β€Ό

A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28772 β€Ό

An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27135 β€Ό

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22715 β€Ό

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Lester 'GaMerZ' Chan WP-CommentNavi plugin <= 1.12.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23650 β€Ό

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27655 β€Ό

xpdf v4.04 was discovered to contain a stack overflow in the component pdftotext.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ MITRE Rolls Out Supply Chain Security Prototype πŸ•΄

Cloud-based System of Trust application now available for test-driving quantitative risk assessment of suppliers of hardware, software, services.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Epidemic of Insecure Storage, Backup Devices Is a Windfall for Cybercriminals πŸ•΄

Enterprise storage devices have 14 security weaknesses on average, putting them at risk of compromise by cyberattackers and especially ransomware attacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ The Board of Directors Will See You Now πŸ•΄

Help the board understand where the business is vulnerable, where controls end, and where exposure begins.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep127: When you chop someone out of a photo, but there they are anyway… ⚠

Listen now - latest episode. Full transcript inside.

πŸ“– Read

via "Naked Security".