usememos/memos makes Incorrect Use of Privileged APIs

In usememos/memos 0.9.0 and prior, a user with login permission can delete all notes of the whole application via `API DELETE https://demo.usememos.com/api/memo/$idnote`. The vulnerability will lose a ...

Continue Reading
usememos/memos Incorrect Use of Privileged APIs vulnerability

In usememos/memos 0.9.0 and prior, a user can archive any private memos, delete any shortcut, and edit any shortcut from other users via API.Read More ...

Continue Reading
GitHub and the Ekoparty 2022 Capture the Flag

As a sponsor of [Ekoparty 2022](), GitHub had the privilege of submitting several challenges to the event's Capture The Flag (CTF) competition. Hubbers from across the company came together to brainst ...

Continue Reading
Admin is able to ARCHIVE OWN Account leads to Deactivate ADMIN Account

# Description As fer the Flow Admin can't ARCHIVE OWN account . i was able to ARCHIVE ADMIN OWN Account by intercept the request and change ID Value to Admin. which leads to ARCHIVED the ADMIN Accou ...

Continue Reading
2022 Annual Metasploit Wrap-Up

![2022 Annual Metasploit Wrap-Up](https://blog.rapid7.com/content/images/2022/12/metasploit-haxmas-candy-canes.jpeg) It's been another gangbusters year for Metasploit, and the holidays are a time to g ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

SUSE SLES15 Security Update : conmon (SUSE-SU-2022:4635-1)

The remote SUSE Linux SLES15 host has a package installed that is affected by a vulnerability as referenced in the SUSE- SU-2022:4635-1 advisory. - A vulnerability was found in CRI-O that causes mem ...

Continue Reading
GuLoader’s Advanced Anti-Analysis Techniques

Threat Level Attack Report For a detailed threat advisory, download the pdf file here Summary GuLoader is an advanced malware downloader that uses polymorphic shellcode to bypass traditional security ...

Continue Reading
[SECURITY] [DLA 3251-1] libcommons-net-java security update

------------------------------------------------------------------------- Debian LTS Advisory DLA-3251-1 [email protected] https://www.debian.org/lts/security/ ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: