โผ CVE-2023-42027 โผ
๐ Read
via "National Vulnerability Database".
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057.๐ Read
via "National Vulnerability Database".
โผ CVE-2017-7252 โผ
๐ Read
via "National Vulnerability Database".
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-46954 โผ
๐ Read
via "National Vulnerability Database".
SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-36022 โผ
๐ Read
via "National Vulnerability Database".
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability๐ Read
via "National Vulnerability Database".
โผ CVE-2023-43018 โผ
๐ Read
via "National Vulnerability Database".
IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 266163.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-36621 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34260 โผ
๐ Read
via "National Vulnerability Database".
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34259 โผ
๐ Read
via "National Vulnerability Database".
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4768 โผ
๐ Read
via "National Vulnerability Database".
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4767 โผ
๐ Read
via "National Vulnerability Database".
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4769 โผ
๐ Read
via "National Vulnerability Database".
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.๐ Read
via "National Vulnerability Database".
๐ด Oracle Enables MFA by Default on Oracle Cloud ๐ด
๐ Read
via "Dark Reading".
Mandatory multifactor authentication is just the latest in Oracle's commitment to have security built-in by default into Oracle Cloud Infrastructure.๐ Read
via "Dark Reading".
Dark Reading
Oracle Enables MFA by Default on Oracle Cloud
Mandatory multifactor authentication is just the latest in Oracle's commitment to have security built-in by default into Oracle Cloud Infrastructure.
๐ด Considerations for Managing Digital Sovereignty: The Executive Perspective ๐ด
๐ Read
via "Dark Reading".
Business leaders must frequently balance the advantages of cloud computing and the free flow of data across geographic borders with the need to abide by local laws and regulations. ๐ Read
via "Dark Reading".
Dark Reading
Considerations for Managing Digital Sovereignty: The Executive Perspective
Business leaders must frequently balance the advantages of cloud computing and the free flow of data across geographic borders with the need to abide by local laws and regulations.
๐ด Ransomware Readiness Assessments: One Size Doesn't Fit All ๐ด
๐ Read
via "Dark Reading".
Tailored ransomware readiness assessments help organizations develop comprehensive response plans that minimize damage and restore operations quickly.๐ Read
via "Dark Reading".
Dark Reading
Ransomware Readiness Assessments: One Size Doesn't Fit All
Tailored ransomware readiness assessments help organizations develop comprehensive response plans that minimize damage and restore operations quickly.
โผ CVE-2023-4591 โผ
๐ Read
via "National Vulnerability Database".
A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3277 โผ
๐ Read
via "National Vulnerability Database".
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address. We are disclosing this issue as the developer has not yet released a patch, but continues to release updates and we escalated this issue to the plugin's team 30 days ago.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-47445 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-4592 โผ
๐ Read
via "National Vulnerability Database".
A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46808 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25960 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop รขโฌโ Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop รขโฌโ Global Dropshipping: from n/a through 1.0.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46859 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.๐ Read
via "National Vulnerability Database".