Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Video Whisper Conference 1.01 Cross Site Scripting

Video Whisper Conference version 1.01 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#google#php#auth
Videoflix CMS 1.3 Insecure Settings

Videoflix CMS version 1.3 appears to leave default credentials installed after installation.

Virtues cpanelCMS 1.0 SQL Injection

Virtues cpanelCMS version 1.0 suffers from a remote SQL injection vulnerability.

CMS BMGI International 4.0 SQL Injection

CMS BMGI International version 4.0 suffers from a remote SQL injection vulnerability.

CVE-2023-37686: Online Nurse Hiring Management System | Nurse Hiring Management Project in PHP

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.

What Doctors Wish You Knew About HIPAA and Data Security

Think US health data is automatically kept private? Think again.

CVE-2023-4009: Ops Manager Server Changelog — MongoDB Ops Manager 5.0

In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.

Digital assets continue to be prime target for malvertisers

Categories: Threat Intelligence Tags: malvertising Tags: nft Tags: crypto Tags: wallet Tags: bing Tags: google NFT enthusiasts are getting their wallets drained after clicking on a malicious ad. (Read more...) The post Digital assets continue to be prime target for malvertisers appeared first on Malwarebytes Labs.