‼ CVE-2023-29132 ‼
📖 Read
via "National Vulnerability Database".
Irssi 1.3.x and 1.4.x before 1.4.4 has a use-after-free because of use of a stale special collector reference. This occurs when printing of a non-formatted line is concurrent with printing of a formatted line.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-26918 ‼
📖 Read
via "National Vulnerability Database".
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29622 ‼
📖 Read
via "National Vulnerability Database".
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29626 ‼
📖 Read
via "National Vulnerability Database".
Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30638 ‼
📖 Read
via "National Vulnerability Database".
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29625 ‼
📖 Read
via "National Vulnerability Database".
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1285 ‼
📖 Read
via "National Vulnerability Database".
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.📖 Read
via "National Vulnerability Database".
🔥1
‼ CVE-2023-29491 ‼
📖 Read
via "National Vulnerability Database".
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.📖 Read
via "National Vulnerability Database".
🔥1
📢 The top malware and ransomware threats for April 2023 📢
📖 Read
via "ITPro".
New ransomware gangs and malware abound as hackers continue to evolve their tactics📖 Read
via "ITPro".
ITPro
The top malware and ransomware threats for April 2023
New ransomware gangs and malware abound as hackers continue to evolve their tactics
‼ CVE-2023-2044 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manipulation of the argument IP-DNS leads to cross site scripting. The attack can be initiated remotely. VDB-225922 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2043 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in Control iD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the component Edit Handler. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-225921 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2047 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Advanced Online Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument voter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225932.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2042 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.5.1. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225920. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2049 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ballot_up.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225934 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2048 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/voters_row.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225933 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
🕴 What the Recent Collapse of SVB Means for Privacy 🕴
📖 Read
via "Dark Reading".
Businesses must be diligent in their actions, cultivate awareness with employees, and implement strict standards around external communications in the wake of Silicon Valley Bank's collapse.📖 Read
via "Dark Reading".
Dark Reading
What the Recent Collapse of SVB Means for Privacy
Businesses must be diligent in their actions, cultivate awareness with employees, and implement strict standards around external communications in the wake of Silicon Valley Bank's collapse.
‼ CVE-2023-26980 ‼
📖 Read
via "National Vulnerability Database".
PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-27643 ‼
📖 Read
via "National Vulnerability Database".
An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2052 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical was found in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ballot_down.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225937 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-26756 ‼
📖 Read
via "National Vulnerability Database".
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-27649 ‼
📖 Read
via "National Vulnerability Database".
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table📖 Read
via "National Vulnerability Database".