Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Beware of Fake Windows 11 Downloads Distributing Vidar Malware

By Waqas Phishing domains are spreading Windows 11 installers loaded with Vidar infostealer. According to the cybersecurity firm Zscaler ThreatLabz,… This is a post from HackRead.com Read the original post: Beware of Fake Windows 11 Downloads Distributing Vidar Malware

HackRead
#web#windows#microsoft#git#backdoor
CVE-2022-29320: Offensive Security’s Exploit Database Archive

MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-26632: Offensive Security’s Exploit Database Archive

Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.

CVE-2022-26634: Offensive Security’s Exploit Database Archive

HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-27095: Offensive Security’s Exploit Database Archive

BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-27092: Offensive Security’s Exploit Database Archive

Private Internet Access v3.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-27094: Offensive Security’s Exploit Database Archive

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-28991: Multi Store Inventory Management System 1.0 Information Disclosure ≈ Packet Storm

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVE-2022-28993: Multi Store Inventory Management System 1.0 Account Takeover ≈ Packet Storm

Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.