Improper Access Control in Crabtyper API

# Description The API program allows any user to create languages and snippets, as well as delete them. This allows a malicious actor to add offensive snippets which could appear to any user, and also ...

Continue Reading
CVE-2022-0217

Unauthenticated Remote Denial of Service Attack in the WebSocket interfaceRead More ...

Continue Reading
CVE-2018-18006

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets of ...

Continue Reading
Virtuozzo 6 : java-1.7.0-openjdk / java-1.7.0-openjdk-demo / etc (VZLSA-2017-2424)

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. ...

Continue Reading
XXE that can Bypass WAF Protection

by Alex Drozdov, Wallarm Research XXE or XML External Entities is a new issue in the 2017 [OWASP Top 10 vulnerability list](). This is the only new issue of the set that was introduced based on direct ...

Continue Reading
CVE-2018-16803

In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.Read More ...

Continue Reading
ruby:2.5 security update

ruby [2.5.9-109.0.1] - Rebuild with a dependency containing fix for Orabug: 33921593 [2.5.9-109] - Properly fix command injection vulnerability in Rdoc. Related: CVE-2021-31799 [2.5.9-108] - Fix comma ...

Continue Reading
AlmaLinux 8 : ruby:2.5 (ALSA-2022:0672)

The remote AlmaLinux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALSA-2022:0672 advisory. - In RDoc 3.11 through 6.x before 6.3.1, as distributed ...

Continue Reading

Back to Main

Subscribe for the latest news: