‼ CVE-2023-2180 ‼
📖 Read
via "National Vulnerability Database".
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22706 ‼
📖 Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <=Â 1.5.48 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1019 ‼
📖 Read
via "National Vulnerability Database".
The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31844 ‼
📖 Read
via "National Vulnerability Database".
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1839 ‼
📖 Read
via "National Vulnerability Database".
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1207 ‼
📖 Read
via "National Vulnerability Database".
This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0812 ‼
📖 Read
via "National Vulnerability Database".
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.📖 Read
via "National Vulnerability Database".
🛠Samhain File Integrity Checker 4.4.10 ðŸ›
📖 Read
via "Packet Storm Security".
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.📖 Read
via "Packet Storm Security".
Packetstormsecurity
Samhain File Integrity Checker 4.4.10 ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
🛠Simple Universal Fortigate Fuzzer ðŸ›
📖 Read
via "Packet Storm Security".
This python script is a tool for fuzzing Fortigate 7.📖 Read
via "Packet Storm Security".
Packetstormsecurity
Simple Universal Fortigate Fuzzer ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
🕴 Microsoft Follina Bug Is Back in Meme-Themed Cyberattacks Against Travel Orgs 🕴
📖 Read
via "Dark Reading".
A two-bit comedian is using a patched Microsoft vulnerability to attack the hospitality industry, and really laying it on thick along the way.📖 Read
via "Dark Reading".
Dark Reading
Microsoft Follina Bug Is Back in Meme-Themed Cyberattacks Against Travel Orgs
A two-bit comedian is using a patched Microsoft vulnerability to attack the hospitality industry, and really laying it on thick along the way.
âš Whodunnit? Cybercrook gets 6 years for ransoming his own employer âš
📖 Read
via "Naked Security".
Not just an active adversary, but a two-faced one, too.📖 Read
via "Naked Security".
Naked Security
Whodunnit? Cybercrook gets 6 years for ransoming his own employer
Not just an active adversary, but a two-faced one, too.
‼ CVE-2023-31627 ‼
📖 Read
via "National Vulnerability Database".
An issue in the strhash component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31623 ‼
📖 Read
via "National Vulnerability Database".
An issue in the mp_box_copy component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31612 ‼
📖 Read
via "National Vulnerability Database".
An issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32787 ‼
📖 Read
via "National Vulnerability Database".
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31621 ‼
📖 Read
via "National Vulnerability Database".
An issue in the kc_var_col component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31616 ‼
📖 Read
via "National Vulnerability Database".
An issue in the bif_mod component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31625 ‼
📖 Read
via "National Vulnerability Database".
An issue in the psiginfo component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31614 ‼
📖 Read
via "National Vulnerability Database".
An issue in the mp_box_deserialize_string function in openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31617 ‼
📖 Read
via "National Vulnerability Database".
An issue in the dk_set_delete component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31609 ‼
📖 Read
via "National Vulnerability Database".
An issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.📖 Read
via "National Vulnerability Database".