Aggregator
CVE-2008-6222 | Joomlashowroom Pro Desk Support Center 1.0 index.php include_file path traversal (EDB-6980 / XFDB-46356)
CVE-2008-6795 | nicLOR Vibro-School-CMS view_news.php nID sql injection (EDB-6981 / XFDB-46348)
CVE-2008-6347 | Luigi Massa Onguma Time Sheet 2.04 lib/onguma.class.php mosConfig_absolute_path code injection (EDB-6976 / BID-32095)
CVE-2008-6268 | Sadi Samami Multi Languages WebShop Online 1.02 detail.php id sql injection (EDB-6974 / XFDB-46369)
CVE-2008-6629 | WEBBDOMAIN WebShop Online 1.02 detail.php name cross site scripting (EDB-6974 / SA32499)
CVE-2008-6267 | Sadi Samami Multi Languages WebShop Online 1.02 detail.php name cross site scripting (EDB-6974 / XFDB-46370)
CVE-2008-6483 | Virtuemart-solutions Com Googlebase 1.1 admin.googlebase.php code injection (EDB-6975 / BID-32098)
CVE-2008-6271 | TBmnet TBmnetCMS 1.0 index.php content path traversal (EDB-6973 / XFDB-46314)
CVE-2008-6272 | Miticdjd Apoll 0.7.5 pass sql injection (EDB-6969 / XFDB-46286)
CVE-2008-6607 | MatPo MatPo Link 1.2 view.php thema cross site scripting (EDB-6971 / BID-32082)
U.S. agency cautions employees to limit phone use due to Salt Typhoon hack of telco providers
.NET 红队武器库和资源合集 (第45期)
.NET内网实战:通过waitfor实现内网权限维持
CVE-2017-7509 | Red Hat Certificate Server 8 certreq input validation (RHSA-2017:2560 / Nessus ID 210259)
CVE-2020-10730 | Samba up to 4.10.16/4.11.10/4.12.3 AD LDAP Server use after free (Bug 1849489 / Nessus ID 210262)
CVE-2016-6814 | Oracle Agile Engineering Data Management 6.2.1.0 Install deserialization (Nessus ID 210264 / ID 20051)
CVE-2016-6814 | Oracle Agile Recipe Management for Pharmaceuticals 9.3.3/9.3.4 Apache Groovy deserialization (Nessus ID 210264 / ID 20051)
CVE-2016-6814 | Oracle Agile PLM MCAD Connector 3.4/3.5/3.6 CAX Client deserialization (Nessus ID 210264 / ID 20051)
Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443) Synology has released fixes for an unauthenticated “zero-click” remote code execution flaw (CVE-2024-10443, aka RISK:STATION) affecting its popular DiskStation and BeeStation network attached storage (NAS) devices. Google patches actively exploited Android vulnerability (CVE-2024-43093) Google has delivered fixes for two vulnerabilities endangering Android users that “may be under limited, targeted exploitation”: … More →
The post Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability appeared first on Help Net Security.