๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-34561 โ€ผ

A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35773 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <=ร‚ 3.1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25443 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator รขโ‚ฌโ€œ easily Button Builder plugin <=ร‚ 2.3.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35778 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <=ร‚ 1.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32104 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <=ร‚ 3.74 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35044 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Drew Phillips Securimage-WP plugin <=ร‚ 3.6.16 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35091 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <=ร‚ 2.10.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-23671 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <=ร‚ 1.1.9.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-36690 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <=ร‚ 4.900 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โš  Apple silently pulls its latest zero-day update โ€“ what now? โš 

Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

๐Ÿ“– Read

via "Naked Security".
โค1
โ€ผ CVE-2023-3620 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2020-20118 โ€ผ

Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-31818 โ€ผ

An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-37659 โ€ผ

xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2746 โ€ผ

The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit this vulnerability, a malicious user would have to convince a user to click on an untrusted link through a social engineering attack or successfully perform a Cross Site Scripting Attack (XSS). Exploitation of a CSRF could potentially lead to sensitive information disclosure and full remote access to the affected products.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2072 โ€ผ

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. ร‚ The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36163 โ€ผ

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36167 โ€ผ

An issue in AVG AVG Anti-Spyware v.7.5 allows an attacker to execute arbitrary code via a crafted script to the guard.exe component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36293 โ€ผ

SQL injection vulnerability in wmanager v.1.0.7 and before allows a remote attacker to obtain sensitive information via a crafted script to the company.php component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36164 โ€ผ

An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-37657 โ€ผ

TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).

๐Ÿ“– Read

via "National Vulnerability Database".