πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-22382 β€Ό

Weak configuration in Automotive while VM is processing a listener request from TEE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28571 β€Ό

Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Ransomware Crisis, Recession Fears Leave CISOs in Tough Spot πŸ•΄

Combining robust decryption and orchestration of encrypted traffic with threat prevention is crucial to staying ahead of attackers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Name That Edge Toon: Office Artifacts πŸ•΄

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-47892 β€Ό

All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47893 β€Ό

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25989 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading toΓ‚ dismiss or the popup.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42508 β€Ό

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5351 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39923 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <=Γ‚ 7.2.7 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4098 β€Ό

It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32792 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within the platform by sending a specifically crafted query to the server. The vulnerability is based on the absence of proper validation of the origin of incoming requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40210 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <=Γ‚ 4.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40202 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <=Γ‚ 3.4.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5353 β€Ό

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40212 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <=Γ‚ 2.1.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4101 β€Ό

The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4102 β€Ό

QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5350 β€Ό

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39159 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <=Γ‚ 2.1.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4103 β€Ό

QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

πŸ“– Read

via "National Vulnerability Database".