Cortex’s Alertmanager can expose local files content via specially crafted config

### Impact A local file inclusion vulnerability exists in Cortex versions v1.13.0, v1.13.1 and v1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously craft ...

Continue Reading
Alist vulnerable to Path Traversal

Alist v3.4.0 is vulnerable to Directory Traversal,Read More ...

Continue Reading
Uncontrolled Resource Consumption

A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to reso ...

Continue Reading
CVE-2022-41040 and CVE-2022-41082 – zero-days in MS Exchange

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/12/19160500/abstract_black_matrix-990x400.jpg) ## Summary At the end of September, GTSC reported an attack on critical infras ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-44456

CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted r ...

Continue Reading
CVE-2022-4599

A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/api/theme-edit/ of the component Product Han ...

Continue Reading
CVE-2022-4596

A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post ...

Continue Reading
CVE-2022-4598

A vulnerability has been found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/api/theme-edit/ of the component ...

Continue Reading

Back to Main

Subscribe for the latest news: