GraphQL – Moderately critical – Cross Site Request Forgery – SA-CONTRIB-2023-051

The GraphQL module enables you to build GraphQL APIs which can include data fetching through Queries and data updates (create, update, delete) through mutations. The module does not sufficiently valid ...

Continue Reading
CVE-2023-43625

A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DL ...

Continue Reading
SugarCRM 13.0.1 Server-Side Template Injection

Post ContentRead More ...

Continue Reading
Non-Human Access is the Path of Least Resistance: A 2023 Recap

2023 has seen its fair share of cyber attacks, however there's one attack vector that proves to be more prominent than others - non-human access. With 11 high-profile attacks in 13 months and an ...

Continue Reading
CVE-2022-39222

A flaw was found in Dex, an identity service that uses OpenID Connect to drive authentication for other apps. This issue may allow an attacker to make a victim navigate to a malicious website and guid ...

Continue Reading
Rocky Linux 8 : php:7.4 (RLSA-2022:6158)

The remote Rocky Linux 8 host has packages installed that are affected by a vulnerability as referenced in the RLSA-2022:6158 advisory. In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1 ...

Continue Reading
php:8.0 security update

libzip php [8.0.30-1] - rebase to 8.0.30 - Resolves: RHEL-11946 php-pear php-pecl-apcu php-pecl-rrd php-pecl-xdebug3...Read More ...

Continue Reading
PHP vulnerability

## Releases * Ubuntu 18.04 ESM * Ubuntu 16.04 ESM ## Packages * php7.0 - HTML-embedded scripting language interpreter * php7.2 - HTML-embedded scripting language interpreter USN-6199-1 fixed a ...

Continue Reading

Back to Main

Subscribe for the latest news: