FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Exploit-DB Updates

[local] Trend Micro OfficeScan Client 10.0 - ACL Service LPE

β€” May 23rd 2023 at 00:00
Trend Micro OfficeScan Client 10.0 - ACL Service LPE
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] WBiz Desk 1.2 - SQL Injection

β€” May 23rd 2023 at 00:00
WBiz Desk 1.2 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Authentication Bypass Erase Account

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Authentication Bypass Erase Account
☐ β˜† βœ‡ Exploit-DB Updates

[local] MobileTrans 4.0.11 - Weak Service Privilege Escalation

β€” May 23rd 2023 at 00:00
MobileTrans 4.0.11 - Weak Service Privilege Escalation
☐ β˜† βœ‡ Exploit-DB Updates

[local] Hubstaff 1.6.14-61e5e22e - 'wow64log' DLL Search Order Hijacking

β€” May 23rd 2023 at 00:00
Hubstaff 1.6.14-61e5e22e - 'wow64log' DLL Search Order Hijacking
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Authentication Bypass Reset Board Config

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Authentication Bypass Reset Board Config
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Stackposts Social Marketing Tool v1.0 - SQL Injection

β€” May 23rd 2023 at 00:00
Stackposts Social Marketing Tool v1.0 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] GetSimple CMS v3.3.16 - Remote Code Execution (RCE)

β€” May 23rd 2023 at 00:00
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Quicklancer v1.0 - SQL Injection

β€” May 23rd 2023 at 00:00
Quicklancer v1.0 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)

β€” May 23rd 2023 at 00:00
Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] ChurchCRM v4.5.4 - Reflected XSS via Image (Authenticated)

β€” May 23rd 2023 at 00:00
ChurchCRM v4.5.4 - Reflected XSS via Image (Authenticated)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)

β€” May 23rd 2023 at 00:00
CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Smart School v1.0 - SQL Injection

β€” May 23rd 2023 at 00:00
Smart School v1.0 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] LeadPro CRM v1.0 - SQL Injection

β€” May 23rd 2023 at 00:00
LeadPro CRM v1.0 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[local] Yank Note v3.52.1 (Electron) - Arbitrary Code Execution

β€” May 23rd 2023 at 00:00
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Unauthenticated Information Disclosure (userManager.cgx)

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Unauthenticated Information Disclosure (userManager.cgx)
☐ β˜† βœ‡ Exploit-DB Updates

[local] Gin Markdown Editor v0.7.4 (Electron) - Arbitrary Code Execution

β€” May 23rd 2023 at 00:00
Gin Markdown Editor v0.7.4 (Electron) - Arbitrary Code Execution
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Authentication Bypass Admin Password Change

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Authentication Bypass Admin Password Change
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Affiliate Me Version 5.0.1 - SQL Injection

β€” May 23rd 2023 at 00:00
Affiliate Me Version 5.0.1 - SQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Authentication Bypass Password Change

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Authentication Bypass Password Change
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] eScan Management Console 14.0.1400.2281 - Cross Site Scripting

β€” May 23rd 2023 at 00:00
eScan Management Console 14.0.1400.2281 - Cross Site Scripting
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] PodcastGenerator 3.2.9 - Multiple Stored Cross-Site Scripting (XSS)

β€” May 23rd 2023 at 00:00
PodcastGenerator 3.2.9 - Multiple Stored Cross-Site Scripting (XSS)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] eScan Management Console 14.0.1400.2281 - SQL Injection (Authenticated)

β€” May 23rd 2023 at 00:00
eScan Management Console 14.0.1400.2281 - SQL Injection (Authenticated)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)

β€” May 23rd 2023 at 00:00
PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)

β€” May 23rd 2023 at 00:00
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] thrsrossi Millhouse-Project 1.414 - Remote Code Execution

β€” May 23rd 2023 at 00:00
thrsrossi Millhouse-Project 1.414 - Remote Code Execution
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] SitemagicCMS 4.4.3 - Remote Code Execution (RCE)

β€” May 23rd 2023 at 00:00
SitemagicCMS 4.4.3 - Remote Code Execution (RCE)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Prestashop 8.0.4 - CSV injection

β€” May 23rd 2023 at 00:00
Prestashop 8.0.4 - CSV injection
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Best POS Management System v1.0 - Unauthenticated Remote Code Execution

β€” May 23rd 2023 at 00:00
Best POS Management System v1.0 - Unauthenticated Remote Code Execution
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Screen SFT DAB 600/C - Authentication Bypass Account Creation

β€” May 23rd 2023 at 00:00
Screen SFT DAB 600/C - Authentication Bypass Account Creation
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)

β€” May 23rd 2023 at 00:00
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-5725-2

β€” May 23rd 2023 at 14:00
Ubuntu Security Notice 5725-2 - USN-5725-1 fixed a vulnerability in Go. This update provides the corresponding update for Ubuntu 16.04 LTS. Diederik Loerakker, Jonny Rhea, RaΓΊl Kripalani, and Preston Van Loon discovered that Go incorrectly handled certain inputs. An attacker could possibly use this issue to cause Go applications to hang or crash, resulting in a denial of service.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6073-9

β€” May 23rd 2023 at 13:59
Ubuntu Security Notice 6073-9 - USN-6073-4 fixed a vulnerability in os-brick. Unfortunately the update introduced a regression with detaching volumes. The security fix has been removed pending further investigation. Jan Wasilewski and Gorka Eguileor discovered that os-brick incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6073-6

β€” May 23rd 2023 at 13:58
Ubuntu Security Notice 6073-6 - USN-6073-1 fixed a vulnerability in Cinder. Unfortunately the update introduced a regression with detaching volumes. The security fix has been removed pending further investigation. Jan Wasilewski and Gorka Eguileor discovered that Cinder incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6073-7

β€” May 23rd 2023 at 13:57
Ubuntu Security Notice 6073-7 - USN-6073-2 fixed a vulnerability in Glance_store. Unfortunately the update introduced a regression with detaching volumes. The security fix has been removed pending further investigation. Jan Wasilewski and Gorka Eguileor discovered that Glance_store incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6073-8

β€” May 23rd 2023 at 13:56
Ubuntu Security Notice 6073-8 - USN-6073-3 fixed a vulnerability in Nova. Unfortunately the update introduced a regression with detaching volumes. The security fix has been removed pending further investigation. Jan Wasilewski and Gorka Eguileor discovered that Nova incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6099-1

β€” May 23rd 2023 at 13:56
Ubuntu Security Notice 6099-1 - It was discovered that ncurses was incorrectly performing bounds checks when processing invalid hashcodes. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. This issue only affected Ubuntu 18.04 LTS. It was discovered that ncurses was incorrectly handling end-of-string characters when processing terminfo and termcap files. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. This issue only affected Ubuntu 18.04 LTS.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Debian Security Advisory 5409-1

β€” May 23rd 2023 at 13:55
Debian Linux Security Advisory 5409-1 - Two security issues have been discovered in libssh, a tiny C SSH library.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6094-1

β€” May 23rd 2023 at 13:55
Ubuntu Security Notice 6094-1 - Zheng Wang discovered that the Intel i915 graphics driver in the Linux kernel did not properly handle certain error conditions, leading to a double-free. A local attacker could possibly use this to cause a denial of service. Jordy Zomer and Alexandra Sandulescu discovered that the Linux kernel did not properly implement speculative execution barriers in usercopy functions in certain situations. A local attacker could use this to expose sensitive information.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6096-1

β€” May 23rd 2023 at 13:54
Ubuntu Security Notice 6096-1 - It was discovered that some AMD x86-64 processors with SMT enabled could speculatively execute instructions using a return address from a sibling thread. A local attacker could possibly use this to expose sensitive information. Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6095-1

β€” May 23rd 2023 at 13:54
Ubuntu Security Notice 6095-1 - Jordy Zomer and Alexandra Sandulescu discovered that the Linux kernel did not properly implement speculative execution barriers in usercopy functions in certain situations. A local attacker could use this to expose sensitive information. Xingyuan Mo discovered that the x86 KVM implementation in the Linux kernel did not properly initialize some data structures. A local attacker could use this to expose sensitive information.
☐ β˜† βœ‡ Exploit-DB Updates

[remote] Optoma 1080PSTX Firmware C02 - Authentication Bypass

β€” May 23rd 2023 at 00:00
Optoma 1080PSTX Firmware C02 - Authentication Bypass
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] TinyWebGallery v2.5 - Remote Code Execution (RCE)

β€” May 23rd 2023 at 00:00
TinyWebGallery v2.5 - Remote Code Execution (RCE)
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] WordPress Plugin Backup Migration 1.2.8 - Unauthenticated Database Backup

β€” May 23rd 2023 at 00:00
WordPress Plugin Backup Migration 1.2.8 - Unauthenticated Database Backup
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Cameleon CMS 2.7.4 - Persistent Stored XSS in Post Title

β€” May 23rd 2023 at 00:00
Cameleon CMS 2.7.4 - Persistent Stored XSS in Post Title
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] Apache Superset 2.0.0 - Authentication Bypass

β€” May 23rd 2023 at 00:00
Apache Superset 2.0.0 - Authentication Bypass
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] PnPSCADA v2.x - Unauthenticated PostgreSQL Injection

β€” May 23rd 2023 at 00:00
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
☐ β˜† βœ‡ Exploit-DB Updates

[webapps] e107 v2.3.2 - Reflected XSS

β€” May 23rd 2023 at 00:00
e107 v2.3.2 - Reflected XSS
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-6093-1

β€” May 22nd 2023 at 16:45
Ubuntu Security Notice 6093-1 - It was discovered that the Traffic-Control Index implementation in the Linux kernel did not properly perform filter deactivation in some situations. A local attacker could possibly use this to gain elevated privileges. Please note that with the fix for this CVE, kernel support for the TCINDEX classifier has been removed. It was discovered that the Traffic-Control Index implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Ubuntu Security Notice USN-5900-2

β€” May 22nd 2023 at 16:45
Ubuntu Security Notice 5900-2 - USN-5900-1 fixed vulnerabilities in tar. This update fixes it to Ubuntu 23.04. It was discovered that tar incorrectly handled certain files. An attacker could possibly use this issue to expose sensitive information or cause a crash.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Red Hat Security Advisory 2023-3245-01

β€” May 22nd 2023 at 16:45
Red Hat Security Advisory 2023-3245-01 - Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Red Hat Security Advisory 2023-3247-01

β€” May 22nd 2023 at 16:45
Red Hat Security Advisory 2023-3247-01 - Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Red Hat Security Advisory 2023-3246-01

β€” May 22nd 2023 at 16:45
Red Hat Security Advisory 2023-3246-01 - Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Red Hat Security Advisory 2023-3243-01

β€” May 22nd 2023 at 16:44
Red Hat Security Advisory 2023-3243-01 - Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Red Hat Security Advisory 2023-3248-01

β€” May 22nd 2023 at 16:44
Red Hat Security Advisory 2023-3248-01 - Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Gentoo Linux Security Advisory 202305-28

β€” May 22nd 2023 at 16:44
Gentoo Linux Security Advisory 202305-28 - Multiple vulnerabilities have been found in snakeyaml, the worst of which could result in denial of service. Versions greater than or equal to 1.33 are affected.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Gentoo Linux Security Advisory 202305-27

β€” May 22nd 2023 at 16:44
Gentoo Linux Security Advisory 202305-27 - A vulnerability has been discovered in Tinyproxy which could be used to achieve memory disclosure. Versions greater than or equal to 1.8.3-r3 are affected.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Gentoo Linux Security Advisory 202305-25

β€” May 22nd 2023 at 16:44
Gentoo Linux Security Advisory 202305-25 - Multiple vulnerabilities have been discovered in ModSecurity Core Rule Set, the worst of which could result in bypassing the WAF. Versions greater than or equal to 3.3.4 are affected.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Gentoo Linux Security Advisory 202305-24

β€” May 22nd 2023 at 16:43
Gentoo Linux Security Advisory 202305-24 - Multiple vulnerabilities have been found in MediaWiki, the worst of which could result in denial of service. Versions greater than or equal to 1.25.2 are affected.
☐ β˜† βœ‡ Advisory Files β‰ˆ Packet Storm

Gentoo Linux Security Advisory 202305-26

β€” May 22nd 2023 at 16:42
Gentoo Linux Security Advisory 202305-26 - Multiple vulnerabilities have been discovered in LibreCAD, the worst of which could result in denial of service. Versions greater than or equal to 2.1.3-r7 are affected.
❌