๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-25061 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24402 โ€ผ

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System รขโ‚ฌโ€œ Booking Calendar plugin <= 2.0.18 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1937 โ€ผ

A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25059 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in avalex GmbH avalex รขโ‚ฌโ€œ Automatically secure legal texts plugin <= 3.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28051 โ€ผ

Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Cybercriminals 'CAN' Steal Your Car, Using Novel IoT Hack ๐Ÿ•ด

Your family's SUV could be gone in the night thanks to a headlight crack and hack attack.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Bad Actors Will Use Large Language Models โ€” but Defenders Can, Too ๐Ÿ•ด

Security teams need to find the best, most effective uses of large language models for defensive purposes.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cybercriminals 'CAN' Steal Your Car, Using Novel IoT Hack ๐Ÿ•ด

Your family's SUV could be gone in the night thanks to a headlight crack and hack attack.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-29236 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25705 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Go Prayer WP Prayer plugin <= 1.9.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25712 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-Buddy Google Analytics Opt-Out plugin <= 2.3.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23885 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-34333 โ€ผ

IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 229698.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25713 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25041 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29094 โ€ผ

Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.20 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-1726 โ€ผ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proliz OBS allows Stored XSS for an authenticated user.This issue affects OBS: before 23.04.01.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25716 โ€ผ

Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25031 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25020 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25711 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPGlobus WPGlobus Translate Options plugin <= 2.1.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".