βΌ CVE-2022-42335 βΌ
π Read
via "National Vulnerability Database".
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed through to cause the hypervisor to access an arbitrary pointer partially under guest control.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26839 βΌ
π Read
via "National Vulnerability Database".
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25490 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist Γ’β¬β Custom Archive Templates plugin <=Γ 1.7.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25710 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <=Γ 1.4.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26843 βΌ
π Read
via "National Vulnerability Database".
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2023-26058 βΌ
π Read
via "National Vulnerability Database".
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26098 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary code.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25347 βΌ
π Read
via "National Vulnerability Database".
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45837 βΌ
π Read
via "National Vulnerability Database".
Reflected Cross-Site Scripting (XSS) vulnerability in Denis ???????? plugin <=Γ 6.0.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27619 βΌ
π Read
via "National Vulnerability Database".
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <=Γ 2.0.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26057 βΌ
π Read
via "National Vulnerability Database".
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25479 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <=Γ 1.3.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-26841 βΌ
π Read
via "National Vulnerability Database".
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.π Read
via "National Vulnerability Database".
π΄ Building a Better SBOM π΄
π Read
via "Dark Reading".
Generating an SBOM is easy. It's generating one that's comprehensive and accurate that's hard.π Read
via "Dark Reading".
Dark Reading
Building a Better SBOM
Generating an SBOM is easy. It's generating one that's comprehensive and accurate that's hard.
π’ How to reduce the risk of phishing and ransomware π’
π Read
via "ITPro".
Top security concerns and tips for mitigation π Read
via "ITPro".
ITPro
How to reduce the risk of phishing and ransomware
Top security concerns and tips for mitigation
βΌ CVE-2023-29779 βΌ
π Read
via "National Vulnerability Database".
Sengled Dimmer Switch V0.0.9 contains a denial of service (DOS) vulnerability, which allows a remote attacker to send malicious Zigbee messages to a vulnerable device and cause crashes. After receiving the malicious command, the device will keep reporting its status and finally drain its battery after receiving the 'Set_short_poll_interval' command.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27105 βΌ
π Read
via "National Vulnerability Database".
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal.π Read
via "National Vulnerability Database".
βΌ CVE-2023-2281 βΌ
π Read
via "National Vulnerability Database".
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.π Read
via "National Vulnerability Database".
β Double zero-day in Chrome and Edge β check your versions now! β
π Read
via "Naked Security".
Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π΄ The Decline in Ransomware: Does It Actually Increase Risks for Organizations? π΄
π Read
via "Dark Reading".
Organizations need to remain vigilant and not take the decline as reason to cut back their cybersecurity strategies.π Read
via "Dark Reading".
Dark Reading
The Decline in Ransomware: Does It Actually Increase Risks for Organizations?
Organizations need to remain vigilant and not take the decline as reason to cut back their cybersecurity strategies.
β PaperCut security vulnerabilities under active attack β vendor urges customers to patch β
π Read
via "Naked Security".
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...π Read
via "Naked Security".
Naked Security
PaperCut security vulnerabilities under active attack β vendor urges customers to patch
If you have the product, but you havenβt patched β well, the crooks have now landed, so please donβt delay. Do it todayβ¦