Security
Headlines
HeadlinesLatestCVEs

Tag

#firefox

CVE-2023-4049: Invalid Bug ID

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVE
#vulnerability#firefox
Codecanyon Bitcoin Tools Suite 1.0 Local File Inclusion

Codecanyon Bitcoin Tools Suite version 1.0 suffers from a local file inclusion vulnerability.

CMVC SHOP LMS 2.1.0 SQL Injection

CMVC SHOP LMS version 2.1.0 suffers from a remote SQL injection vulnerability.

CMSninesol 1.0 Cross Site Scripting

CMSninesol version 1.0 suffers from a cross site scripting vulnerability.

CVE-2023-34635: Wifi Soft Unibox Administration 3.0

Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

Apple iOS, Google Android Patch Zero-Days in July Security Updates

Plus: Mozilla fixes two high-severity bugs in Firefox, Citrix fixes a flaw that was used to attack a US-based critical infrastructure organization, and Oracle patches over 500 vulnerabilities.

CVE-2023-3990: 政务版存在xss跨站脚本攻击 · Issue #I7K4DQ · 铭飞/MCMS - Gitee.com

A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-235611.

XLAgenda 4.4 Cross Site Request Forgery

XLAgenda version 4.4 suffers from a cross site request forgery vulnerability.

WonderCMS 0.6-Beta Password Disclosure

WonderCMS version 0.6-Beta suffers from a password disclosure vulnerability.