compras.agi.com.br Cross Site Scripting vulnerability OBB-3124447

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
astrobiology.nasa.gov Open Redirect vulnerability OBB-3124450

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
mypride.jukesolutions.com Open Redirect vulnerability OBB-3124499

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
Admin is able to ARCHIVE OWN Account leads to Deactivate ADMIN Account

# Description As fer the Flow Admin can't ARCHIVE OWN account . i was able to ARCHIVE ADMIN OWN Account by intercept the request and change ID Value to Admin. which leads to ARCHIVED the ADMIN Accou ...

Continue Reading
CVE-2022-4549

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2022-4295

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
2022 Annual Metasploit Wrap-Up

![2022 Annual Metasploit Wrap-Up](https://blog.rapid7.com/content/images/2022/12/metasploit-haxmas-candy-canes.jpeg) It's been another gangbusters year for Metasploit, and the holidays are a time to g ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-43396

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd para ...

Continue Reading

Back to Main

Subscribe for the latest news: