πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-5255 β€Ό

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4911 β€Ό

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ USPS Anchors Snowballing Smishing Campaigns πŸ•΄

Researchers found 164 domains connected to a single threat actor located in Tehran.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Attacks on Maximum Severity WS_FTP Bug Have Been Limited β€” So Far πŸ•΄

While CVE-2023-40044 is critical, threat watchers hope it won't be another MOVEit for customers of Progress Software's file transfer technology.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33272 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39645 β€Ό

Theme volty tvcmspaymenticon up to v4.0.1 was discovered to contain a SQL injection vulnerability via the component /tvcmspaymenticon/ajax.php?action=update_position&recordsArray.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43176 β€Ό

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43953 β€Ό

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33270 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43898 β€Ό

Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40519 β€Ό

A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33268 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44973 β€Ό

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33271 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33273 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43951 β€Ό

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43952 β€Ό

SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33269 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40830 β€Ό

Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44974 β€Ό

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".