๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-32746 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <=ร‚ 1.6.45 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41559 โ€ผ

Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-27426 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Notifyvisitors NotifyVisitors plugin <=ร‚ 1.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-33929 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joaquรƒยญn Ruiz Easy Admin Menu plugin <=ร‚ 1.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32793 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <=ร‚ 2.0.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41557 โ€ผ

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41563 โ€ผ

Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41561 โ€ผ

Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32802 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <=ร‚ 1.9.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-33320 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mohammad I. Okfie WP-Hijri plugin <=ร‚ 1.5.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41555 โ€ผ

Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25019 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <=ร‚ 3.0.9 versions

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32962 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite รขโ‚ฌโ€œ Wishlist for WooCommerce plugin <=ร‚ 1.3.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Should Senior IT Professionals Be Accountable for Professional Decisions? ๐Ÿ•ด

Everyone makes mistakes โ€” but what if your mistakes risk the security of millions of people?

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ iOS 16 Cheat Sheet: Complete Guide for 2023 ๐Ÿฆฟ

Learn about the features available with iOS 16 and how to download and install the latest version of Apple's mobile operating system.

๐Ÿ“– Read

via "Tech Republic".
โค1
โ€ผ CVE-2023-34176 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <=ร‚ 1.2.9 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-3992 โ€ผ

The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34172 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <=ร‚ 3.0.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-4013 โ€ผ

The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34032 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pascal Casier bbPress Toolkit plugin <=ร‚ 1.0.12 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34023 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Miled WordPress Social Login plugin <=ร‚ 3.0.4 versions.

๐Ÿ“– Read

via "National Vulnerability Database".