π¦Ώ E-Waste: Australiaβs Hidden ESG Nightmare π¦Ώ
π Read
via "Tech Republic".
Australia has an e-waste problem, and for all the conversations around climate change, energy use, plastics and other ESG matters, it's surprising that more isn't said about it.π Read
via "Tech Republic".
TechRepublic
E-Waste: Australia's Hidden ESG Nightmare
Despite strides in sustainability, plastics recycling and other ESG matters, Australia lacks effective e-waste recycling standards.
βΌ CVE-2023-36670 βΌ
π Read
via "National Vulnerability Database".
A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30383 βΌ
π Read
via "National Vulnerability Database".
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38257 βΌ
π Read
via "National Vulnerability Database".
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information, including user login names and encrypted passwords.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37477 βΌ
π Read
via "National Vulnerability Database".
1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality `/hosts/firewall/ip` endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. This issue has been addressed in commit `e17b80cff49` which is included in release version `1.4.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37480 βΌ
π Read
via "National Vulnerability Database".
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit a weakness in the connector template upload feature to upload a malicious zip bomb file, resulting in resource exhaustion and service unavailability for all users of the Fides webserver. This vulnerability affects Fides versions `2.11.0` through `2.15.1`. Exploitation is limited to users with elevated privileges with the `CONNECTOR_TEMPLATE_REGISTER` scope, which includes root users and users with the owner role. The vulnerability has been patched in Fides version `2.16.0`. Users are advised to upgrade to this version or later to secure their systems against this threat. There is no known workaround to remediate this vulnerability without upgrading. If an attack occurs, the impact can be mitigated by manually or automatically restarting the affected container.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34330 βΌ
π Read
via "National Vulnerability Database".
AMI SPx contains a vulnerability in the BMC where a User may cause a improper control of generation of code by Dynamic Redfish Extension. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.Γ π Read
via "National Vulnerability Database".
βΌ CVE-2020-22159 βΌ
π Read
via "National Vulnerability Database".
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36669 βΌ
π Read
via "National Vulnerability Database".
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35763 βΌ
π Read
via "National Vulnerability Database".
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encrypted passwords into plaintext.π Read
via "National Vulnerability Database".
βΌ CVE-2023-33329 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <=Γ 2.4.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28019 βΌ
π Read
via "National Vulnerability Database".
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37788 βΌ
π Read
via "National Vulnerability Database".
goproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.π Read
via "National Vulnerability Database".
βΌ CVE-2023-33312 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wppal Easy Captcha plugin <=Γ 1.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37481 βΌ
π Read
via "National Vulnerability Database".
Fides is an open-source privacy engineering platform for managing data privacy requests and privacy regulations. The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit this vulnerability to upload zip files containing malicious SVG bombs (similar to a billion laughs attack), causing resource exhaustion in Admin UI browser tabs and creating a persistent denial of service of the 'new connector' page (`datastore-connection/new`). This vulnerability affects Fides versions `2.11.0` through `2.15.1`. Exploitation is limited to users with elevated privileges with the `CONNECTOR_TEMPLATE_REGISTER` scope, which includes root users and users with the owner role. The vulnerability has been patched in Fides version `2.16.0`. Users are advised to upgrade to this version or later to secure their systems against this threat. There is no known workaround to remediate this vulnerability without upgrading.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35189 βΌ
π Read
via "National Vulnerability Database".
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an unauthenticated user to upload a malicious payload and execute it.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28020 βΌ
π Read
via "National Vulnerability Database".
Γ URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34329 βΌ
π Read
via "National Vulnerability Database".
AMI SPx contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, and availability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37758 βΌ
π Read
via "National Vulnerability Database".
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28021 βΌ
π Read
via "National Vulnerability Database".
The BigFix WebUI uses weak cipher suites.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37522 βΌ
π Read
via "National Vulnerability Database".
SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js.π Read
via "National Vulnerability Database".