Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

WARNING: New Unpatched Microsoft Exchange Zero-Day Under Active Exploitation

Security researchers are warning of previously undisclosed flaws in fully patched Microsoft Exchange servers being exploited by malicious actors in real-world attacks to achieve remote code execution on affected systems. That's according to Vietnamese cybersecurity company GTSC, which discovered the shortcomings as part of its security monitoring and incident response efforts in August 2022. The

The Hacker News
#vulnerability#web#windows#microsoft#js#backdoor#rce#zero_day#The Hacker News
CVE-2022-2778: Security Advisory 2022-15

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

Aunalytics Launches Security Patching Platform as a Service

Expedited software patching and updating recognized as one of the most important processes to protect against system compromise from cyberattacks.

CVE-2022-40472: ZKBio Time - CSV Injection

ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.

A Matrix Update Patches Serious End-to-End Encryption Flaws

The messenger protocol had gained popularity for its robust security, but vulnerabilities allowed attackers to decrypt messages and impersonate users.

qdPM 9.1 Authenticated Shell Upload

A remote code execution vulnerability exists in qdPM versions 9.1 and below. An attacker can upload a malicious PHP code file via the profile photo functionality by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature thus allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

Online Examination System 1.0 SQL Injection

Online Examination System version 1.0 suffers from a remote SQL injection vulnerability.

Online Examination System 1.0 Cross Site Scripting

Online Examination System version 1.0 suffers from a cross site scripting vulnerability.