βΌ CVE-2023-31068 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41593 βΌ
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41256 βΌ
π Read
via "National Vulnerability Database".
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40032 βΌ
π Read
via "National Vulnerability Database".
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31069 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.π Read
via "National Vulnerability Database".
βΌ CVE-2020-19323 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication requiredπ Read
via "National Vulnerability Database".
βΌ CVE-2023-39068 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N32RA-KL-V3 v.YK_HZXM_NBD80N32RA-KL_V4.03.R11.7601.Nat.OnvifC.20220120.bin allows a remote attacker to casue a denial of service via a crafted request to the service.XM component.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31468 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39067 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL.π Read
via "National Vulnerability Database".
βΌ CVE-2020-19320 βΌ
π Read
via "National Vulnerability Database".
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41609 βΌ
π Read
via "National Vulnerability Database".
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.π Read
via "National Vulnerability Database".
βΌ CVE-2023-41103 βΌ
π Read
via "National Vulnerability Database".
Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a JavaScript payload.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39780 βΌ
π Read
via "National Vulnerability Database".
ASUS RT-AX55 v3.0.0.4.386.51598 was discovered to contain an authenticated command injection vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2020-19319 βΌ
π Read
via "National Vulnerability Database".
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38829 βΌ
π Read
via "National Vulnerability Database".
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38743 βΌ
π Read
via "National Vulnerability Database".
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39070 βΌ
π Read
via "National Vulnerability Database".
An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in token.cpp:1934.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39063 βΌ
π Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.π Read
via "National Vulnerability Database".
π΄ Iran's Charming Kitten Pounces on Israeli Exchange Servers π΄
π Read
via "Dark Reading".
Archrivals face off in the cyber plane, as opportunistic hackers prey on the unpatched and generally negligent.π Read
via "Dark Reading".
Dark Reading
Iran's Charming Kitten Pounces on Israeli Exchange Servers
Archrivals face off in the cyber plane, as opportunistic hackers prey on the unpatched and generally negligent.
π΄ Cloudflare Announces Unified Data Protection Suite to Address Risks of Modern Coding and Increased AI Use π΄
π Read
via "Dark Reading".
Rich security suite enables seamless and secure path to transition corporate networks to the cloud, and accelerate innovation.π Read
via "Dark Reading".
Dark Reading
Cloudflare Announces Unified Data Protection Suite to Address Risks of Modern Coding and Increased AI Use
Rich security suite enables seamless and secure path to transition corporate networks to the cloud, and accelerate innovation.
π΄ Google and Acalvio Partner to Deliver Active Defense to Protect Customers From Advanced Threats π΄
π Read
via "Dark Reading".
π Read
via "Dark Reading".
Dark Reading
Google and Acalvio Partner to Deliver Active Defense to Protect Customers From Advanced Threats
Security is a top priority for all customers on Google Cloud, whether beginner, intermediate, or advanced users. Through our partnership with Acalvio, we are able to offer Active Defense to Google Cloud customers, providing automated deception managementβ¦