CVE-2022-4187 - Exploiting Insufficient Policy Enforcement in Chrome DevTools for Local File Access on Windows
Date Discovered: Late 2022
Affected Software: Google Chrome on Windows (prior to 108..5359.71)
Severity: Medium (Chromium Security Severity)
Exploit Type: Insufficient policy enforcement,
CVE-2022-4189 An attacker could bypass navigation restrictions in Chrome with a malicious extension if they convince a user to install it.
This issue was fixed in version 108.0.5359.81. In Google Chrome prior to 108.0.5359.71, an attacker could convince a user
CVE-2022-4176 An out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker to exploit heap corruption via UI interactions.
This issue was fixed in version 9.5.5.5. The issue existed due to a race condition where the out of bounds write could
CVE-2022-36962 - Remote Command Injection in SolarWinds Platform Explained
---
Introduction
In late 2022, a significant vulnerability was discovered in the SolarWinds Platform: CVE-2022-36962. This flaw openly allowed remote attackers with control over
CVE-2022-4034 - CSV Injection in Appointment Hour Booking Plugin for WordPress (Up to v1.3.72) — Step-by-step Exploit Explained
If you run a WordPress site and rely on plugins to manage bookings, security must be a constant concern. A recently disclosed vulnerability, CVE-2022-
Episode
00:00:00
00:00:00