πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2014-4525

Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-4523

Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Chrome Affected By Magellan 2.0 Flaws ❌

Researchers warn that five vulnerabilities that stem from SQLite could enable remote code execution.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-1000029

Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1000028

Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4695

Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4693

WordPress Xorbin Digital Flash Clock 1.0 has XSS

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4691

Sencha Labs Connect has XSS with connect.methodOverride()

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4665

SPBAS Business Automation Software 2012 has CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4664

SPBAS Business Automation Software 2012 has XSS.

πŸ“– Read

via "National Vulnerability Database".
⚠ Christmas malware uses β€œSupport Greta Thunberg” as a lure ⚠

You're invited to a climate demonstration... but to find the time and place, you need to open an attachment. Don't do it!

πŸ“– Read

via "Naked Security".
πŸ” Friday Five: 12/27 Edition πŸ”

A phishing attack targets PayPal customers, two bugs are discovered in the Twitter Android app, and a cyber attack causes flight cancellations in Alaska - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2013-5027

Collabtive 1.0 has incorrect access control

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4985

Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4982

AVTECH AVN801 DVR has a security bypass via the administration login captcha

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4976

Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4975

Hikvision DS-2CD7153-E IP Camera has Privilege Escalation

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4868

Karotz API 12.07.19.00: Session Token Information Disclosure

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4867

Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4859

INSTEON Hub 2242-222 lacks Web and API authentication

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4796

ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request

πŸ“– Read

via "National Vulnerability Database".