βΌ CVE-2023-30483 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <=Γ 3.3.9.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29097 βΌ
π Read
via "National Vulnerability Database".
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in a3rev Software a3 Portfolio plugin <=Γ 3.1.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30475 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin Γ’β¬β Coupon Affiliates plugin <=Γ 5.4.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31041 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30754 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly Γ’β¬β Ad Manager, AdSense Ads & Ads.Txt plugin <=Γ 1.8.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30751 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <=Γ 1.0.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30752 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <=Γ 2.0.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30477 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Essitco AFFILIATE Solution plugin <=Γ 1.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28535 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <=Γ 2.2.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30489 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <=Γ 1.2.16 versions.π Read
via "National Vulnerability Database".
π΄ Health Data of 4M Stolen in Cl0p MOVEit Breach of Colorado Department π΄
π Read
via "Dark Reading".
State's Department of Health Care Policy & Financing is the latest to acknowledge an attack by the Russian group's ongoing exploitation of third-party systems.π Read
via "Dark Reading".
Dark Reading
Health Data of 4M Stolen in Cl0p MOVEit Breach of Colorado Department
State's Department of Health Care Policy & Financing is the latest to acknowledge an attack by the Russian group's ongoing exploitation of third-party systems.
π jSQL Injection 0.91 π
π Read
via "Packet Storm Security".
jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the source code release.π Read
via "Packet Storm Security".
Packetstormsecurity
jSQL Injection 0.91 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2023-40359 βΌ
π Read
via "National Vulnerability Database".
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28768 βΌ
π Read
via "National Vulnerability Database".
Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1), and XS1930-10 firmware versionΓ V4.80(ABQE.1) could allow an unauthenticated LAN-based attacker to cause denial-of-service (DoS) conditions by sending crafted frames to an affected switch.π Read
via "National Vulnerability Database".
βΌ CVE-2023-33013 βΌ
π Read
via "National Vulnerability Database".
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40354 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4322 βΌ
π Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.π Read
via "National Vulnerability Database".
π¦Ώ Massive EvilProxy Phishing Attack Campaign Bypasses 2FA, Targets Top-Level Executives π¦Ώ
π Read
via "Tech Republic".
This attack sent approximately 120,000 phishing emails to organizations worldwide with the goal to steal Microsoft 365 credentials.π Read
via "Tech Republic".
TechRepublic
Massive EvilProxy Phishing Attack Campaign Bypasses 2FA, Targets Top-Level Executives
This attack sent approximately 120,000 phishing emails to organizations worldwide with the goal to steal Microsoft 365 credentials.
π΄ Russian-African Security Gathering Exposes Kremlin's Reduced Influence π΄
π Read
via "Dark Reading".
Messaging from joint summit in Saint Petersburg amounts to little more than "diplomatic subterfuge," observers note.π Read
via "Dark Reading".
Dark Reading
Russian-African Security Gathering Exposes Kremlin's Reduced Influence
Messaging from joint summit in Saint Petersburg amounts to little more than "diplomatic subterfuge," observers note.
π΄ What's New in the NIST Cybersecurity Framework 2.0 π΄
π Read
via "Dark Reading".
Update to the NIST framework adds new "govern" function for cybersecurity.π Read
via "Dark Reading".
Dark Reading
What's New in the NIST Cybersecurity Framework 2.0
Update to the NIST framework adds new "govern" function for cybersecurity.
βΌ CVE-2023-39293 βΌ
π Read
via "National Vulnerability Database".
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.π Read
via "National Vulnerability Database".