๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-35780 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Andy Whalen Galleria plugin <=ร‚ 1.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24417 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in tiggersWelt.Net Worthy plugin <=ร‚ 1.6.5-6497609 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-3269 โ€ผ

A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25706 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Pagup WordPress Robots.Txt optimization plugin <=ร‚ 1.4.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34029 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <=ร‚ 2.3.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36522 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <=ร‚ 1.5.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34185 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <=ร‚ 0.5.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35047 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <=ร‚ 1.3.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34561 โ€ผ

A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35773 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <=ร‚ 3.1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25443 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator รขโ‚ฌโ€œ easily Button Builder plugin <=ร‚ 2.3.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35778 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <=ร‚ 1.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32104 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <=ร‚ 3.74 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35044 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Drew Phillips Securimage-WP plugin <=ร‚ 3.6.16 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35091 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <=ร‚ 2.10.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-23671 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <=ร‚ 1.1.9.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-36690 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <=ร‚ 4.900 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โš  Apple silently pulls its latest zero-day update โ€“ what now? โš 

Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

๐Ÿ“– Read

via "Naked Security".
โค1
โ€ผ CVE-2023-3620 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2020-20118 โ€ผ

Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-31818 โ€ผ

An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

๐Ÿ“– Read

via "National Vulnerability Database".