βΌ CVE-2023-4147 βΌ
π Read
via "National Vulnerability Database".
A use-after-free flaw was found in the Linux kernelΓ’β¬β’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3671 βΌ
π Read
via "National Vulnerability Database".
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as adminπ Read
via "National Vulnerability Database".
βΌ CVE-2023-4205 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds memory access flaw was found in the Linux kernelΓ’β¬β’s do_journal_end function when the fails array-index-out-of-bounds in fs/reiserfs/journal.c could happen. This flaw allows a local user to crash the system.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3650 βΌ
π Read
via "National Vulnerability Database".
The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).π Read
via "National Vulnerability Database".
βΌ CVE-2023-3575 βΌ
π Read
via "National Vulnerability Database".
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacksπ Read
via "National Vulnerability Database".
βΌ CVE-2023-27373 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3524 βΌ
π Read
via "National Vulnerability Database".
The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scriptingπ Read
via "National Vulnerability Database".
βΌ CVE-2021-24916 βΌ
π Read
via "National Vulnerability Database".
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.π Read
via "National Vulnerability Database".
βΌ CVE-2023-2843 βΌ
π Read
via "National Vulnerability Database".
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.π Read
via "National Vulnerability Database".
βΌ CVE-2023-36220 βΌ
π Read
via "National Vulnerability Database".
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38795 βΌ
π Read
via "National Vulnerability Database".
In Gitea through 1.17.1, repo cloning can occur in the migration function.π Read
via "National Vulnerability Database".
π΄ SANS Teaches Cybersecurity Leadership in Saudi Arabia π΄
π Read
via "Dark Reading".
Infosecurity learning modules will cover security planning, policy, and leadership.π Read
via "Dark Reading".
Dark Reading
SANS Teaches Cybersecurity Leadership in Saudi Arabia
Infosecurity learning modules will cover security planning, policy, and leadership.
π΄ Mallox Ransomware Group Revamps Malware Variants, Evasion Tactics π΄
π Read
via "Dark Reading".
The group continues to target SQL servers, adding the Remcos RAT, BatCloak, and Metasploit in an attack that shows advance obfuscation methods.π Read
via "Dark Reading".
Dark Reading
Mallox Ransomware Group Revamps Malware Variants, Evasion Tactics
The group continues to target SQL servers, adding the Remcos RAT, BatCloak, and Metasploit in an attack that shows advance obfuscation methods.
π1
π¦Ώ ChatGPT Security Concerns: Credentials on the Dark Web and More π¦Ώ
π Read
via "Tech Republic".
ChatGPT-related security risks also include writing malicious code and amplifying disinformation. Read about a new tool advertised on the Dark Web called WormGPT.π Read
via "Tech Republic".
TechRepublic
ChatGPT Security Concerns: Credentials on the Dark Web and More
ChatGPT-related security risks also include writing malicious code and amplifying disinformation. Read about WormGPT.
βΌ CVE-2023-38044 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38045 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23758 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-32783 βΌ
π Read
via "National Vulnerability Database".
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34476 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23757 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-34477 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.π Read
via "National Vulnerability Database".