βΌ CVE-2023-28127 βΌ
π Read
via "National Vulnerability Database".
A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.π Read
via "National Vulnerability Database".
βοΈ Microsoft Patch Tuesday, May 2023 Edition βοΈ
π Read
via "Krebs on Security".
Microsoft today released software updates to fix at least four dozen security holes in its Windows operating systems and other software, including patches for two zero-day vulnerabilities that are already being exploited in active attacks.π Read
via "Krebs on Security".
Krebs on Security
Microsoft Patch Tuesday, May 2023 Edition
Microsoft today released software updates to fix at least four dozen security holes in its Windows operating systems and other software, including patches for two zero-day vulnerabilities that are already being exploited in active attacks.
βΌ CVE-2023-25833 βΌ
π Read
via "National Vulnerability Database".
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victimΓ’β¬β’s browser (no stateful change made or customer data rendered).π Read
via "National Vulnerability Database".
βΌ CVE-2022-36330 βΌ
π Read
via "National Vulnerability Database".
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code executionΓ in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: through 9.4.0-191; ibi: through 9.4.0-191.Γ π Read
via "National Vulnerability Database".
βΌ CVE-2023-30777 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <=Γ 6.1.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22361 βΌ
π Read
via "National Vulnerability Database".
Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote authenticated attacker to alter a WebUI password of the product.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27385 βΌ
π Read
via "National Vulnerability Database".
Heap-based buffer overflow vulnerability exists in CX-Drive All models V3.01 and earlier. By having a user open a specially crafted SDD file, arbitrary code may be executed and/or information may be disclosed.π Read
via "National Vulnerability Database".
βΌ CVE-2023-32570 βΌ
π Read
via "National Vulnerability Database".
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.π Read
via "National Vulnerability Database".
βΌ CVE-2023-24392 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Full Width Banner Slider Wp plugin <=Γ 1.1.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27889 βΌ
π Read
via "National Vulnerability Database".
Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of a user and to perform unintended operations by having a user view a malicious page.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22711 βΌ
π Read
via "National Vulnerability Database".
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Agent Evolution IMPress Listings plugin <=Γ 2.6.2 versions.π Read
via "National Vulnerability Database".
β Low-level motherboard security keys leaked in MSI breach, claim researchers β
π Read
via "Naked Security".
What can you do if someone steals your keys but you can't change the lock? We explain the dilemma in plain English.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π’ Capita cyber attack could cost firm up to $25 million in fees π’
π Read
via "ITPro".
Capitaβs costs in the wake of a cyber attack could exceed expectations, experts have warned π Read
via "ITPro".
ITPro
Capita cyber attack could cost firm up to $25 million in fees
Capitaβs costs in the wake of a cyber attack could exceed expectations, experts have warned
π’ How the channel can help secure the future of work π’
π Read
via "ITPro".
Hybrid work security issues pose challenges for businesses, but this is where the channel has an opportunity to step in and support partners π Read
via "ITPro".
channelpro
How the channel can help secure the future of work
Hybrid work security issues pose challenges for businesses, but this is where the channel has an opportunity to step in and support partners
β Bootkit zero-day fix β is this Microsoftβs most cautious patch ever? β
π Read
via "Naked Security".
When blocking buggy bootup modules, you have to be really careful not to lock your keys inside the car...π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
βΌ CVE-2022-47137 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <=Γ 4.3.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-46861 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plugin <=Γ 6.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47600 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <=Γ 1.1.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47423 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <=Γ 4.4.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-27856 βΌ
π Read
via "National Vulnerability Database".
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <=Γ 4.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47436 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MantraBrain Yatra plugin <=Γ 2.1.14 versions.π Read
via "National Vulnerability Database".