QRadar Community Edition 7.3.1.6 Server Side Request Forgery Vulnerability

QRadar Community Edition version 7.3.1.6 has an issue where the RssFeedItem class of the QRadar web application is used to fetch and parse RSS feeds. No validation is performed on the user-supplied RS ...

Continue Reading
QRadar Community Edition 7.3.1.6 Server Side Request Forgery

Post ContentRead More ...

Continue Reading
SALTO ProAccess SPACE 5.5 Traversal / File Write / XSS / Bypass Vulnerabilities

SALTO ProAccess SPACE versions 5.5 and below suffer from path traversal, arbitrary file write, persistent cross site scripting, privilege escalation, and clear text transmission of sensitive data vuln ...

Continue Reading
SALTO ProAccess SPACE 5.5 Traversal / File Write / XSS / Bypass

Post ContentRead More ...

Continue Reading
MyEtherWallet: Local Storage Custom Node Credentials Leak

## Summary Credentials for a custom node are stored in plain text inside Local Storage on the user's machine. If this node is configured in a certain way this could lead to the theft of any funds in a ...

Continue Reading
CVE-2019-11895

A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC ...

Continue Reading
CVE-2019-11892

A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's confi ...

Continue Reading
P4wnP1 A.L.O.A. – Framework Which Turns A Rapsberry Pi Zero W Into A Flexible, Low-Cost Platform For Pentesting, Red Teaming And Physical Engagements

[![](https://1.bp.blogspot.com/-kAfpXyhBA0g/XOS89ORP25I/AAAAAAAAO9U/ohWV8x2YZRoU8uw-JNH2-J2fUP6QWvIXQCLcBGAs/s640/raspberry%2Bpi%2Bzero.jpg)]() P4wnP1 A.L.O.A. by MaMe82 is a framework which turns a R ...

Continue Reading

Back to Main

Subscribe for the latest news: