Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-38185

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE
#vulnerability#microsoft#rce
CVE-2023-35394

Azure HDInsight Jupyter Notebook Spoofing Vulnerability

CVE-2023-36881

Azure Apache Ambari Spoofing Vulnerability

CVE-2023-38188

Azure Apache Hadoop Spoofing Vulnerability

CVE-2023-36877

Azure Apache Oozie Spoofing Vulnerability

CVE-2023-35393

Azure Apache Hive Spoofing Vulnerability

CVE-2023-37646: Bitberry Software produces a growing range of products for Windows PCs, and has been doing so since 2000

An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.

CVE-2023-39532: fix(fix): Censor spread import · endojs/endo@fc90c64

SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the confinement of guest applications under SES that may manifest as either the ability to exfiltrate information or execute arbitrary code depending on the configuration and implementation of the surrounding host. Guest program running inside a Compartment with as few as no endowments can gain access to the surrounding host’s dynamic import by using dynamic import after the spread operator, like `{...import(arbitraryModuleSpecifier)}`. On the web or in web extensions, a Content-Security-Policy following ordinary best practices likely mitigates both the risk of exfiltration and execution of arbitrary code, at least limiting the modules that the attacker can import to those that are already part of the application...

CVE-2023-38773: GitHub - 0x72303074/CVE-Disclosures

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php.

CVE-2023-3386

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection.This issue affects Camera Trap Tracking System: before 3.1905.