CVE-2022-38652 An insecuar deserialization vulnerability exists in VMWare Hyperic Agent 5.8.6
The supported products at the time of this advisory are VMWare Workstation 15, 16, and 17; VMWare Fusion 8, 9, and 10; and VMWare Player
CVE-2022-43671 In Zoho ManageEngine Password Manager Pro, PAM360, and Access Manager Plus before 4306, SQL Injection is possible.
Accessing the password database using the password reset functionality may allow an attacker to gain access to the system or account. A remote attacker may
CVE-2022-45193 CBRN-Analysis before 22 has weak file permissions, which might lead to disclosure of file contents or privilege escalation.
This results in the ability for an attacker to download and install malicious software on a system through compromised email or through a drive-by-
CVE-2022-41882 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer
enabled` system config to `false`. As an additional security measure, users should consider upgrading their Nextcloud server to version 3.6.1. More information on
CVE-2022-41904 Element iOS is a Matrix client based on the MatrixSDK. Before version 1.9.7, events encrypted using Megolm that could not be trusted were unmarked.
On the Android mobile operating system, Element supports Android 4.1 or later. On Android, Element is accessed through the Google Play Store. Element iOS
Episode
00:00:00
00:00:00