AList vulnerable to Improper Preservation of Permissions

Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).Read More ...

Continue Reading
Virtuozzo Hybrid Infrastructure 5.3 Update 1 (5.3.1-38)

This update provides new features for security, monitoring, and the compute service, as well as bug fixes and improvements. **Vulnerability id:** VSTOR-60452 It is impossible to start a cluster update ...

Continue Reading
Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Apache CXF Server-Side Request Forgery vulnerability

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices tha ...

Continue Reading
Apache CXF Server-Side Request Forgery vulnerability

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices tha ...

Continue Reading
Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS / 22.10 : containerd vulnerabilities (USN-5776-1)

The remote Ubuntu 18.04 LTS / 20.04 LTS / 22.04 LTS / 22.10 host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5776-1 advisory. - containerd is an ope ...

Continue Reading
CVE-2022-46364

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices tha ...

Continue Reading

Back to Main

Subscribe for the latest news: