Security
Headlines
HeadlinesLatestCVEs

Tag

#chrome

CVE-2023-27707: DedeCMS V5.7.160 Backend Blind SQL Injection

SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.

CVE
#sql#csrf#vulnerability#web#mac#apple#intel#php#chrome#webkit
CVE-2023-27130: Typecho <= 1.2.0 Admin System with Reflected-XSS Vulnerability · Issue #1535 · typecho/typecho

Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter.

CVE-2023-27250: bug_report/sql_injection.md at main · iknownt/bug_report

Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.

CVE-2023-26912: Stored xss vulnerability exists in order evaluation(订单评价存在XSS漏洞) · Issue #37 · xenv/S-mall-ssm

Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb 17, 2020, allows local attackers to execute arbitrary code via the evaluate button.

Stellar Cyber Launches InterSTELLAR Partner Program for Open XDR Solutions

By Owais Sultan Stellar Cyber, the company that recently made headlines as one of the “10 Hot XDR Security Companies You… This is a post from HackRead.com Read the original post: Stellar Cyber Launches InterSTELLAR Partner Program for Open XDR Solutions

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild. Eight of the 80 bugs are rated Critical, 71 are rated Important, and one is rated Moderate in severity. The updates are in addition to 29 flaws the tech giant fixed in its Chromium-based Edge browser in recent weeks. The

Google Proposes Reducing TLS Cert Life Span to 90 Days

Organizations will likely have until the end of 2024 to gain visibility and control over their keys and certificates.

CVE-2023-28343: Disclosures/os_command_injection.md at main · ahmedalroky/Disclosures

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

CVE-2023-24892

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability