πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28409 β€Ό

Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-20012 β€Ό

WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27926 β€Ό

Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25953 β€Ό

Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2844 β€Ό

Missing Authorization in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25946 β€Ό

Authentication bypass vulnerability in Qrio Lock (Q-SL2) firmware version 2.0.9 and earlier allows a network-adjacent attacker to analyze the product's communication data and conduct an arbitrary operation under certain conditions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31826 β€Ό

Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31670 β€Ό

An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27507 β€Ό

MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28408 β€Ό

Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27387 β€Ό

Cross-site request forgery (CSRF) in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to conduct an arbitrary operation by having a logged-in user view a malicious page. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22654 β€Ό

Client-side enforcement of server-side security issue exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may lead to an arbitrary script execution on a logged-in user's web browser. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28413 β€Ό

Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31740 β€Ό

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28394 β€Ό

Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the application on the PC where the affected product is installed. As a result, an arbitrary OS command may be executed as well.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25440 β€Ό

Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27923 β€Ό

Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27514 β€Ό

OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbitrary OS command.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26595 β€Ό

Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ PyPI attack: Targeting of repository 'shows no sign of stopping' πŸ“’

Greater collaboration and understanding of attackers’ tactics is key to mitigating open source security threats

πŸ“– Read

via "ITPro".
⚠ Phone scamming kingpin gets 13 years for running β€œiSpoof” service ⚠

Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

πŸ“– Read

via "Naked Security".