โผ CVE-2023-40303 โผ
๐ Read
via "National Vulnerability Database".
GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.๐ Read
via "National Vulnerability Database".
๐ด 5 Ways CISA Can Help Cyber-Poor Small Businesses & Local Governments ๐ด
๐ Read
via "Dark Reading".
Adopting these recommendations will help SMBs and public-sector agencies that must deal with the same questions of network security and data safety as their larger cousins, but without the same resources.๐ Read
via "Dark Reading".
Dark Reading
5 Ways CISA Can Help Cyber-Poor Small Businesses & Local Governments
Adopting these recommendations will help SMBs and public-sector agencies that must deal with the same questions of network security and data safety as their larger cousins, but without the same resources.
โผ CVE-2023-30186 โผ
๐ Read
via "National Vulnerability Database".
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30187 โผ
๐ Read
via "National Vulnerability Database".
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30188 โผ
๐ Read
via "National Vulnerability Database".
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37847 โผ
๐ Read
via "National Vulnerability Database".
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37070 โผ
๐ Read
via "National Vulnerability Database".
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)๐ Read
via "National Vulnerability Database".
โ Crimeware server used by NetWalker ransomware seized and shut down โ
๐ Read
via "Naked Security".
The site was running from 2014 and allegedly raked in more than $20m, which the DOJ is seeking to claw back...๐ Read
via "Naked Security".
Sophos News
Naked Security โ Sophos News
๐ข Stealthy Kerberoasting attacks surge and lend support to latest ransomware trend ๐ข
๐ Read
via "ITPro".
Kerberoasting techniques could be emerging as a viable alternative to traditional ransomware attacks, experts have warned ๐ Read
via "ITPro".
ITPro
Stealthy Kerberoasting attacks surge and lend support to latest ransomware trend
Kerberoasting techniques could be emerging as a viable alternative to traditional ransomware attacks, experts have warned
๐ด Following Pushback, Zoom Says It Won't Use Customer Data to Train AI Models ๐ด
๐ Read
via "Dark Reading".
Company's experience highlights the tightrope tech organizations walk when integrating AI into their products and services.๐ Read
via "Dark Reading".
Dark Reading
Following Pushback, Zoom Says It Won't Use Customer Data to Train AI Models
Company's experience highlights the tightrope tech organizations walk when integrating AI into their products and services.
โผ CVE-2023-30749 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ihomefinder Optima Express + MarketBoost IDX Plugin plugin <=ร 7.3.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30483 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <=ร 3.3.9.2 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-29097 โผ
๐ Read
via "National Vulnerability Database".
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in a3rev Software a3 Portfolio plugin <=ร 3.1.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30475 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin รขโฌโ Coupon Affiliates plugin <=ร 5.4.5 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-31041 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30754 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly รขโฌโ Ad Manager, AdSense Ads & Ads.Txt plugin <=ร 1.8.5 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30751 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <=ร 1.0.2 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30752 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <=ร 2.0.1 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30477 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Essitco AFFILIATE Solution plugin <=ร 1.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-28535 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <=ร 2.2.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-30489 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <=ร 1.2.16 versions.๐ Read
via "National Vulnerability Database".