CVE Notify
19.4K subscribers
4 photos
223K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2023-28144
KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race conditions involving symlinks and elevate_perf_privileges.sh chown calls.

πŸŽ–@cveNotify
🚨 CVE-2023-26262
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

πŸŽ–@cveNotify
🚨 CVE-2023-28425
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.

πŸŽ–@cveNotify
🚨 CVE-2023-27578
Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages exists. Due to this issue, an attacker can modify or delete any Galaxy Visualization or Galaxy Page given they know the encoded ID of it. Additionally, they can copy or import any Galaxy Visualization given they know the encoded ID of it. Patches are available for versions 22.01, 22.05, and 23.0. For the changes to take effect, you must restart all Galaxy server processes. There are no supported workarounds.

πŸŽ–@cveNotify
🚨 CVE-2023-0681
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the β€˜page’ parameter of the β€˜data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.

πŸŽ–@cveNotify
🚨 CVE-2023-26511
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.

πŸŽ–@cveNotify
🚨 CVE-2021-3293
emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

πŸŽ–@cveNotify
🚨 CVE-2023-1379
A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223127.

πŸŽ–@cveNotify
🚨 CVE-2023-1416
A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223128.

πŸŽ–@cveNotify
🚨 CVE-2023-1418
A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument transactioncode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223129 was assigned to this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2023-23402
Windows Media Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2022-45124
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff network traffic to leverage this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2022-43663
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2023-23393
Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23394
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23395
Microsoft SharePoint Server Spoofing Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23396
Microsoft Excel Denial of Service Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23399
Microsoft Excel Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23398
Microsoft Excel Spoofing Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-23403
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

πŸŽ–@cveNotify