AWS VDP: Amazon Comprehend Medical Service Reporting “AWS Internal” for CloudTrail Events Generated from FIPS Endpoints

The Comprehend Medical service was found to have 8 API endpoints that incorrectly reported the user-agent and network information as "AWS Internal" in CloudTrail event logs. This beh ...

Continue Reading
egmanton-pm.org.uk Cross Site Scripting vulnerability OBB-4030710

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
computerauswertung.at Cross Site Scripting vulnerability OBB-4027597

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
odaah.com Cross Site Scripting vulnerability OBB-4027599

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
dix-immobilien.de Cross Site Scripting vulnerability OBB-4027574

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
semillas-de-marihuana.com Improper Access Control vulnerability OBB-4027568

Following the coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. notified th ...

Continue Reading
WakaTime: User Email Disclosure via ID-Based Invitation

The issue occurs when inviting a user by their WakaTime ID. If a user has set their email to private, their email address was disclosed when they were invited using their ID. This contradicted the pri ...

Continue Reading
PortSwigger Web Security: Burp Suite extensions can execute arbitrary code

Vulnerability description not...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: