โผ CVE-2022-48538 โผ
๐ Read
via "National Vulnerability Database".
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37434 โผ
๐ Read
via "National Vulnerability Database".
Multiple vulnerabilities in the web-based managementร interface of EdgeConnect SD-WAN Orchestrator could allowร an authenticated remote attacker to conduct SQL injectionร attacks against the EdgeConnect SD-WAN Orchestratorร instance. An attacker could exploit these vulnerabilities toร ร obtain and modify sensitive information in the underlyingร database potentially leading to the exposure and corruptionร of sensitive data controlled by the EdgeConnect SD-WANร Orchestrator host.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-20813 โผ
๐ Read
via "National Vulnerability Database".
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-38666 โผ
๐ Read
via "National Vulnerability Database".
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-39599 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45611 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-21687 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24514 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-25887 โผ
๐ Read
via "National Vulnerability Database".
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37424 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability in the web-based management interfaceร of EdgeConnect SD-WAN Orchestrator could allow anร unauthenticated remote attacker to run arbitrary commands onร the underlying host if certain preconditions outside of theร attacker's control are met. Successful exploitation of thisร vulnerability could allow an attacker to execute arbitraryร commands on the underlying operating system leading toร complete system compromise.๐ Read
via "National Vulnerability Database".
๐ด Controversial Cybercrime Law Passes in Jordan ๐ด
๐ Read
via "Dark Reading".
The increase in cyberattacks against the Middle East in the last few years has pressured Jordan and other nations to better secure their infrastructures.๐ Read
via "Dark Reading".
Dark Reading
Controversial Cybercrime Law Passes in Jordan
The increase in cyberattacks against the Middle East in the last few years has pressured Jordan and other nations to better secure their infrastructures.
๐ด Adobe Patches Critical Deserialization Vulnerability, but Exploits Persist ๐ด
๐ Read
via "Dark Reading".
The vulnerability was being exploited in the wild, targeting two versions of Adobe ColdFusion. ๐ Read
via "Dark Reading".
Dark Reading
Adobe Patches Critical Deserialization Vulnerability, but Exploits Persist
The vulnerability was being exploited in the wild, targeting two versions of Adobe ColdFusion.
๐ด Forescout Joins MISA and Announces Integration With Microsoft Sentinel ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Forescout Joins MISA and Announces Integration With Microsoft Sentinel
San Jose, CA. August 22, 2023 โ Forescout, a global cybersecurity leader, today announced integrations with Microsoft Sentinel as part of a broader initiative to support the Microsoft Security portfolio. These integrations will deliver real-time visibilityโฆ
๐ด Absolute Dental Services Notifies Patients of Data Security Incident ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Absolute Dental Services Notifies Patients of Data Security Incident
DURHAM, N.C., Aug. 22, 2023 /PRNewswire/ -- Absolute Dental Services ("ADS") is a dental laboratory which experienced a data security incident that may have impacted personal or protected health information belonging to certain individuals who received dentalโฆ
๐ด Grip Security Raising $41M Series B Led by Third Point Ventures ๐ด
๐ Read
via "Dark Reading".
๐ Read
via "Dark Reading".
Dark Reading
Grip Security Raising $41M Series B Led by Third Point Ventures
BOSTON โ (BUSINESS WIRE) โ Grip Security, a leader in SaaS identity risk management, today announced it is raising $41 million in Series B funding led by Third Point Ventures, with participation from YL Ventures, Intel Capital, and The Syndicate Group. Theโฆ
๐ฆฟ Generative AI: Cybersecurity Weapon, But Not Without Adaptable, Creative (Human) Thinkers ๐ฆฟ
๐ Read
via "Tech Republic".
Cybersecurity expert Kayne McGladrey speaks about why AI cannot do what creative people can, and the important role of generative AI in SOCs.๐ Read
via "Tech Republic".
TechRepublic
Generative AI: Cybersecurity Weapon, But Not Without Adaptable, Creative (Human) Thinkers
Cybersecurity expert Kayne McGladrey speaks about why AI cannot do what creative people can, and the important role of generative AI in SOCs.
๐ด Study: More Than Half of Browser Extensions Pose Security Risks ๐ด
๐ Read
via "Dark Reading".
Spin.AI's risk assessment of some 300,000 browser extensions had overly permissive access and could execute potentially malicious behaviors.๐ Read
via "Dark Reading".
Dark Reading
More Than Half of Browser Extensions Pose Security Risks
Spin.AI's risk assessment of some 300,000 browser extensions found 51% had overly permissive access and could execute potentially malicious behaviors.
โผ CVE-2023-33850 โผ
๐ Read
via "National Vulnerability Database".
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2023-38734 โผ
๐ Read
via "National Vulnerability Database".
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-38733 โผ
๐ Read
via "National Vulnerability Database".
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-40370 โผ
๐ Read
via "National Vulnerability Database".
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470.๐ Read
via "National Vulnerability Database".