Denial Of Service (DoS)

github.com/grafana/grafana is vulnerable to Denial Of Service (DoS). The vulnerability exists due to executing concurrent mixed queries through the `executeConcurrentQueries` function of `query.go`, w ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

CVE-2023-35809

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the REST API. By using a crafted request, custom PHP code ...

Continue Reading
MStore API < 3.9.8 – Unauthenticated Blind SQLi

The plugin does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owne ...

Continue Reading
MStore API < 3.9.9 – Unauthenticated Privilege Escalation

The plugin does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plug ...

Continue Reading
Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive Disruptions

[![Massive DDoS Attack](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft on Friday attributed a string of service outage ...

Continue Reading
GitLab: Account takeover due to insufficient URL validation on RelayState parameter

Hi, I have found an issue which can be used by an attacker to steal Bitbucket access token along with Other third party access tokens(google, salesforce etc). But the most important one is bitbucket. ...

Continue Reading
FreeBSD : transmission-daemon — vulnerable to dns rebinding attacks (3e5b8bd3-0c32-452f-a60e-beab7b762351)

Google Project Zero reports : The transmission bittorrent client uses a client/server architecture, the user interface is the client which communicates to the worker daemon using JSON RPC requests. As ...

Continue Reading
CVE-2017-12117

An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the re ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: