πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-38947 β€Ό

An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33364 β€Ό

An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-38948 β€Ό

An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-0956 β€Ό

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39075 β€Ό

Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38942 β€Ό

Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36217 β€Ό

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32764 β€Ό

Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35081 β€Ό

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-42986 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-39122. Reason: This candidate is a reservation duplicate of CVE-2023-39122. Notes: All CVE users should reference CVE-2023-39122 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
🦿 Could C2PA Cryptography be the Key to Fighting AI-Driven Misinformation? 🦿

Adobe, Arm, Intel, Microsoft and Truepic put their weight behind C2PA, an alternative to watermarking AI-generated content.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-3749 β€Ό

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39121 β€Ό

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33666 β€Ό

ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4002 β€Ό

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38941 β€Ό

django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36137 β€Ό

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

πŸ“– Read

via "National Vulnerability Database".