πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-39645 β€Ό

Theme volty tvcmspaymenticon up to v4.0.1 was discovered to contain a SQL injection vulnerability via the component /tvcmspaymenticon/ajax.php?action=update_position&recordsArray.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43176 β€Ό

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43953 β€Ό

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33270 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43898 β€Ό

Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40519 β€Ό

A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33268 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44973 β€Ό

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33271 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33273 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43951 β€Ό

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43952 β€Ό

SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33269 β€Ό

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40830 β€Ό

Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44974 β€Ό

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Russian Hacktivism Takes a Toll on Organizations in Ukraine, EU, US πŸ•΄

Russian hacktivist attacks are mostly for show, but sometimes they cause serious damage and are poised to begin getting worse.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-39648 β€Ό

Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module Ò€œTheme Volty CMS TestimonialҀ� (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39647 β€Ό

Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module Ò€œTheme Volty CMS Category ProductҀ� (tvcmscategoryproduct) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39651 β€Ό

Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module Ò€œTheme Volty CMS BrandListҀ� (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39646 β€Ό

Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module Ò€œTheme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

πŸ“– Read

via "National Vulnerability Database".