Vulnerabilities & Exploits

Securezoo Cybersecurity Threat Center blog posts of new vulnerabilities and exploits.

CISA adds Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added a Critical Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to its Known Exploited Vulnerabilities Catalog.

CISA adds Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to Known Exploited Vulnerabilities Catalog Read More »

Samba patches 5 vulnerabilities, 1 rated High severity (CVE-2022-32744)

Samba has released software updates to fix five vulnerabilities in multiple Samba software products. One of the fixed issues could allow Samba AD users to forge password change requests for any user.

Samba patches 5 vulnerabilities, 1 rated High severity (CVE-2022-32744) Read More »

PrestaShop websites vulnerable to major SQL Injection attacks

PrestaShop websites are reported vulnerable to a major SQL Injection vulnerability (tracked as CVE-2022-36408) and have been exploited in the wild since July 2022.

PrestaShop websites vulnerable to major SQL Injection attacks Read More »

Oracle Critical Patch Update for July 2022

Oracle has released its Critical Patch Update for July 2022 to include 349 vulnerability fixes across multiple products. The updates also include fixes for Log4j and Spring Framework vulnerabilities.

Oracle Critical Patch Update for July 2022 Read More »

Apple patches vulnerabilities in iOS 15.6, macOS Monterey 12.5, and other products

Apple has released security updates for Apple iOS 15.6, iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8, macOS Catalina, tvOS 15.6, watchOS 8.7, and Safari 15.6.

Apple patches vulnerabilities in iOS 15.6, macOS Monterey 12.5, and other products Read More »

Google releases Chrome 103 (103.0.5060.134) security updates with fixes for 5 High severity vulnerabilities

Google has released Chrome version 103.0.5060.134 for Windows, Mac and Linux, with fixes for five High severity vulnerabilities. Additionally, Google also published new security updates for ChromeOS and Android.

Google releases Chrome 103 (103.0.5060.134) security updates with fixes for 5 High severity vulnerabilities Read More »

Cyber actors continue to exploit Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon Systems (updated)

The Cybersecurity and Infrastructure Security Agency (CISA) warns cyber actors continue to exploit Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon Systems.

Cyber actors continue to exploit Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon Systems (updated) Read More »