Cyber Newsroom Feed
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
- Zero Day Initiative
The February 2024 Security Update Review
None ... Read more
- 0patch.com
Micropatches For Another Remote Windows Event Log Denial Of Service ("LogCrusher", no CVE)
While recently patching the (still 0day) "EventLogCrasher" vulnerability, we came across another similar vulnerability published in January 2023 by Dolev Taler, a security researcher at Varonis.Dolev' ... Read more
- Zero Day Initiative
CVE-2023-46263: Ivanti Avalanche Arbitrary File Upload Vulnerability
None ... Read more
- 0patch.com
Micropatches Released For Microsoft Windows XAML diagnostics API Elevation of Privilege (CVE-2023-36003)
December 2023 Windows Updates brought a patch for CVE-2023-36003, a privilege escalation vulnerability in Microsoft Windows XAML diagnostics API. The vulnerability allows a low-privileged Windows proc ... Read more
- cert.pl
Vulnerabilities in Hongdian Router H8951-4G-ESP software
CVE ID CVE-2023-49253 Publication date 12 January 2024 Vendor Hongdian Product H8951-4G-ESP Vulnerable versions before build 2310271149 Vulnerability type (CWE) Use of Hard-coded Credentials (CWE-798) ... Read more
- cert.pl
Vulnerability in Kofax Capture software
CVE ID CVE-2023-5118 Publication date 11 January 2024 Vendor Kofax Product Capture Vulnerable versions through 11.0.0 Vulnerability type (CWE) Stored XSS (CWE-79) Report source Report to CERT Polska D ... Read more
- cert.pl
Vulnerability in TCExam software
CVE ID CVE-2023-6554 Publication date 11 January 2024 Vendor Tecnick.com Product TCExam Vulnerable versions All below 15.1.0 Vulnerability type (CWE) Missing Authorization (CWE-862) Report source Own ... Read more
- cert.pl
Vulnerability in PrestaShop Google Integrator software
CVE ID CVE-2023-6921 Publication date 08 January 2024 Vendor PrestaShow Product PrestaShop Google Integrator Vulnerable versions All below 2.1.4 Vulnerability type (CWE) SQL injection (CWE-89) Report ... Read more
- cert.pl
Vulnerability in TasmoAdmin software
CVE ID CVE-2023-6552 Publication date 08 January 2024 Vendor TasmoAdmin Product TasmoAdmin Vulnerable versions All below 3.3.0 Vulnerability type (CWE) URL Redirection to Untrusted Site (CWE-601) Repo ... Read more
- cert.pl
Vulnerability in class.upload.php open source library
CVE ID CVE-2023-6551 Publication date 04 January 2024 Vendor Colin Verot Product class.upload.php Vulnerable versions All Vulnerability type (CWE) Improper Input Validation (CWE-20) Report source Own ... Read more