โผ CVE-2023-46153 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <=ร 1.0.9 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-44219 โผ
๐ Read
via "National Vulnerability Database".
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-46199 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <=ร 4.1.1 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34057 โผ
๐ Read
via "National Vulnerability Database".
VMware Tools contains a local privilege escalation vulnerability.ร A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34059 โผ
๐ Read
via "National Vulnerability Database".
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper.ร A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-46194 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist รขโฌโ Custom Archive Templates plugin <=ร 1.7.5 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-46093 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <=ร 2.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34058 โผ
๐ Read
via "National Vulnerability Database".
VMware Tools contains a SAML token signature bypass vulnerability.ร A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html ร in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .๐ Read
via "National Vulnerability Database".
โผ CVE-2023-46192 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <=ร 1.2.3 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-44220 โผ
๐ Read
via "National Vulnerability Database".
SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.๐ Read
via "National Vulnerability Database".
๐ฆฟ Protect Your Passwords for Life for Just $25 ๐ฆฟ
๐ Read
via "Tech Republic".
Automatically create and save passwords, fill in forms and logins, even securely share passwords and sync across all of your devices via WiFi.๐ Read
via "Tech Republic".
TechRepublic
Get 2 Lifetime Password Manager Subscriptions for Only $50
Save your business time and money with Sticky Password Premium and get this two-account bundle for $49.99 at TechRepublic Academy.
โผ CVE-2023-5817 โผ
๐ Read
via "National Vulnerability Database".
The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5774 โผ
๐ Read
via "National Vulnerability Database".
The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.๐ Read
via "National Vulnerability Database".
๐ Falco 0.36.2 ๐
๐ Read
via "Packet Storm Security".
Sysdig Falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about Falco as a mix between snort, ossec and strace.๐ Read
via "Packet Storm Security".
Packetstormsecurity
Falco 0.36.2 โ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
โผ CVE-2023-5705 โผ
๐ Read
via "National Vulnerability Database".
The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-44376 โผ
๐ Read
via "National Vulnerability Database".
Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add2' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5807 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection.This issue affects Education Portal: before 3.2023.29.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-44377 โผ
๐ Read
via "National Vulnerability Database".
Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'add3' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5570 โผ
๐ Read
via "National Vulnerability Database".
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Account Footprinting.This issue affects Home Manager Gateway: before v.1.27.12.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5821 โผ
๐ Read
via "National Vulnerability Database".
The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-5820 โผ
๐ Read
via "National Vulnerability Database".
The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.๐ Read
via "National Vulnerability Database".