Cyber Newsroom Feed
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
- cert.pl
Vulnerability in Kofax Capture software
CVE ID CVE-2023-5118 Publication date 11 January 2024 Vendor Kofax Product Capture Vulnerable versions through 11.0.0 Vulnerability type (CWE) Stored XSS (CWE-79) Report source Report to CERT Polska D ... Read more
- cert.pl
Vulnerability in TCExam software
CVE ID CVE-2023-6554 Publication date 11 January 2024 Vendor Tecnick.com Product TCExam Vulnerable versions All below 15.1.0 Vulnerability type (CWE) Missing Authorization (CWE-862) Report source Own ... Read more
- cert.pl
Vulnerability in TasmoAdmin software
CVE ID CVE-2023-6552 Publication date 08 January 2024 Vendor TasmoAdmin Product TasmoAdmin Vulnerable versions All below 3.3.0 Vulnerability type (CWE) URL Redirection to Untrusted Site (CWE-601) Repo ... Read more
- cert.pl
Vulnerability in PrestaShop Google Integrator software
CVE ID CVE-2023-6921 Publication date 08 January 2024 Vendor PrestaShow Product PrestaShop Google Integrator Vulnerable versions All below 2.1.4 Vulnerability type (CWE) SQL injection (CWE-89) Report ... Read more
- cert.pl
Vulnerability in class.upload.php open source library
CVE ID CVE-2023-6551 Publication date 04 January 2024 Vendor Colin Verot Product class.upload.php Vulnerable versions All Vulnerability type (CWE) Improper Input Validation (CWE-20) Report source Own ... Read more
- cert.pl
Vulnerability in CoolKit Technology eWeLink mobile application (Android & iOS)
CVE ID CVE-2023-6998 Publication date 30 December 2023 Vendor CoolKit Technology Product eWeLink (Android & iOS) Vulnerable versions All below 5.2.0 Vulnerability type (CWE) Improper Privilege Managem ... Read more
- cert.pl
Vulnerability in MegaBIP and SmodBIP software
CVE ID CVE-2023-5378 Publication date 20 December 2023 Vendor Jan Syski Product SmodBIP and MegaBIP Vulnerable versions SmodBIP: all, MegaBIP: all through 4.36.2 Vulnerability type (CWE) Improper Inpu ... Read more
- cert.pl
Russian Foreign Intelligence Service (SVR) Cyber Actors Use JetBrains TeamCity CVE in Global Targeting
The Federal Bureau of Investigation (FBI), US Cybersecurity & Infrastructure Security Agency (CISA), National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CER ... Read more
- cert.pl
Vulnerability in SAS 9.4 software
CVE ID CVE-2023-4932 Publication date 12 December 2023 Vendor SAS Institute Product SAS Vulnerable versions 9.4_M7 and 9.4_M8 Vulnerability type (CWE) Reflected XSS (CWE-79) Report source Report to CE ... Read more
- 0patch.com
Free Micropatches For Microsoft Access Forced Authentication Through Firewall (0day)
Update 2/14/2024: Either January 30 or February 1 Office update brought a fix for this issue: now, Access warns the user for any ODBC connection to SQL Server. Our patch only shows a warning when such ... Read more