๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25K subscribers
88.4K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-45071 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web รขโ‚ฌโ€œ Mobile-Friendly Drag & Drop Contact Form Builder plugin <=ร‚ 1.15.18 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45073 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Koch Mendeley Plugin plugin <=ร‚ 1.3.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32088 โ€ผ

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-31217 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MyTechTalky User Location and IP plugin <=ร‚ 1.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46004 โ€ผ

Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45067 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <=ร‚ 2.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46006 โ€ผ

Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32089 โ€ผ

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45608 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Nicola Modugno Smart Cookie Kit plugin <=ร‚ 2.3.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ What Australian IT Leaders Need to Focus on Ahead of Privacy Act Reforms ๐Ÿฆฟ

The Australian federal government aims to deliver changes to privacy laws in 2024. Organisations are being warned to prepare ahead of time by creating a comprehensive map of organisational data.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2023-45607 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <=ร‚ 6.3.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45630 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery รขโ‚ฌโ€œ Image and Video Gallery with Thumbnails plugin <=ร‚ 2.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45604 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <=ร‚ 4.0.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30781 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Theme Blvd Tweeple plugin <=ร‚ 0.9.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5631 โ€ผ

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attackerto load arbitrary JavaScript code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45602 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <=ร‚ 5.785 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45632 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <=ร‚ 1.5.22 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45628 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <=ร‚ 0.2.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด North Korea's Kimsuky Doubles Down on Remote Desktop Control ๐Ÿ•ด

The sophisticated APT employs various tactics to abuse Windows and other built-in protocols with both custom and public malware to take over victim systems.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ ExpressVPN Review (2023): Pricing, Features, Pros, & Cons ๐Ÿฆฟ

Editor has the option to alter SEO's meta description or write their own DEK to draw readers into the article most effectively. Alternatively, editor can assign DEK writing to the assigned writer. Consider the top picks or major editorial call-outs for inclusion.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ•ด D-Link Confirms Breach, Rebuts Hacker's Claims About Scope ๐Ÿ•ด

The router specialist says the attacker's claims to have heisted millions and millions of records are significantly overblown. But an incident did happen, stemming from a successful phish.

๐Ÿ“– Read

via "Dark Reading".