โผ CVE-2023-24094 โผ
๐ Read
via "National Vulnerability Database".
An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1134 โผ
๐ Read
via "National Vulnerability Database".
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27096 โผ
๐ Read
via "National Vulnerability Database".
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26959 โผ
๐ Read
via "National Vulnerability Database".
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-47925 โผ
๐ Read
via "National Vulnerability Database".
The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a DoS of the process answering the current request while having no effect on other requests.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1138 โผ
๐ Read
via "National Vulnerability Database".
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1136 โผ
๐ Read
via "National Vulnerability Database".
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1133 โผ
๐ Read
via "National Vulnerability Database".
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1140 โผ
๐ Read
via "National Vulnerability Database".
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1135 โผ
๐ Read
via "National Vulnerability Database".
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1145 โผ
๐ Read
via "National Vulnerability Database".
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1142 โผ
๐ Read
via "National Vulnerability Database".
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-22707 โผ
๐ Read
via "National Vulnerability Database".
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift รขโฌโ animation and page builder blocks plugin <= 4.9.9 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-27296 โผ
๐ Read
via "National Vulnerability Database".
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick [2] to solve it. [1] https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [2] https://github.com/apache/inlong/pull/7422 https://github.com/apache/inlong/pull/7422๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26958 โผ
๐ Read
via "National Vulnerability Database".
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1655 โผ
๐ Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.๐ Read
via "National Vulnerability Database".
โ Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store โ
๐ Read
via "Naked Security".
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.๐ Read
via "Naked Security".
Sophos News
Naked Security โ Sophos News
๐ด Drive to Pervasive Encryption Boosts Key Management ๐ด
๐ Read
via "Dark Reading".
Key vaults, aka key management as a service (KMaaS), promise to allow companies to encrypt sensitive data across cloud and third parties with granular control.๐ Read
via "Dark Reading".
Dark Reading
Drive to Pervasive Encryption Boosts Key Management
Key vaults, aka key-management-as-a-service (KMaaS), promise to allow companies to encrypt sensitive data across cloud and third parties with granular control.
๐ด 7 Women Leading the Charge in Cybersecurity Research & Analysis ๐ด
๐ Read
via "Dark Reading".
From rising stars to veterans heading up research teams, check out our profiles of women making a big impact in cyber defense as the threat landscape expands.๐ Read
via "Dark Reading".
Dark Reading
7 Women Leading the Charge in Cybersecurity Research & Analysis
From rising stars to veterans heading up research teams, check out our profiles of women making a big impact in cyber defense as the threat landscape expands.
โผ CVE-2023-0589 โผ
๐ Read
via "National Vulnerability Database".
The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0498 โผ
๐ Read
via "National Vulnerability Database".
The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack๐ Read
via "National Vulnerability Database".