🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2015-9384

The relevant plugin before 1.0.8 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9408

The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9407

The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9405

The wp-piwik plugin before 1.0.5 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9404

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9403

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9402

The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9401

The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9400

The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9399

The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9398

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9397

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9396

The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file= XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9395

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9394

The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9393

The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9392

The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.

📖 Read

via "National Vulnerability Database".
🔏 Friday Five: 9/20 Edition 🔏

A popular password manager fixes a bug, a 20 million person breach, and more - catch up on the week's infosec and privacy news with this week's Friday Five!

📖 Read

via "Subscriber Blog RSS Feed ".
🕴 Ransomware Strikes 49 School Districts & Colleges in 2019 🕴

The education sector has seen 10 new victims in the past nine days alone, underscoring a consistent trend throughout 2019.

📖 Read

via "Dark Reading: ".
Facebook Removed Tens of Thousands of Apps Post-Cambridge Analytica

Facebook said it has suspended and banned tens of thousands of apps on its platform after its investigation, launched after Cambridge Analytica, into how they collect and use data.

📖 Read

via "Threatpost".
🔐 How to avoid the dreaded Video4Linux flaw in Android 🔐

With Google dragging its feet on the fix for Video4Linux, you might consider revoking camera permissions for certain apps.

📖 Read

via "Security on TechRepublic".