CVE-2022-3176 The Linux kernel has a use-after-free bug in io_uring's signalfd_poll() and binder_poll() that send POLLFREE notifications before the waitqueue is freed.
Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the
CVE-2022-2912 The Craw Data WP plugin through 1.0.0 is vulnerable to SSRF as it doesn't have nonce checks.
To discover if you’re vulnerable to SSRF, you can attempt to perform a malicious search query. If you don’t have any plugin enabled
CVE-2022-38534 TOTOLINK-720R v4.1.5cu.374 had a remote code execution vulnerability.
An attacker may leverage this vulnerability to take control of an affected device.
TOTOLINK-720R v4.1.5cu.374 was also discovered to contain several
CVE-2022-40655 Attackers can execute arbitrary code on NIKON NIS-Elements Viewer installations.
An attacker can also create a specially crafted file that is saved to the system directory of a target and then execute this file. All
CVE-2022-40663 Attackers can execute arbitrary code on NIKON NIS-Elements Viewer installations.
An attacker can leverage known vectors such as insecure content in social media sites or email messages, or lurking remote attackers to conduct a click-
Episode
00:00:00
00:00:00