rocksdb vulnerable to out-of-bounds read

Affected versions of this crate called the RocksDB C API `rocksdb_open_column_families_with_ttl()` with a pointer to a single integer TTL value, but one TTL value for each column family is expected. T ...

Continue Reading
rocksdb vulnerable to out-of-bounds read

Affected versions of this crate called the RocksDB C API `rocksdb_open_column_families_with_ttl()` with a pointer to a single integer TTL value, but one TTL value for each column family is expected. T ...

Continue Reading
Facebook’s In-app Browser on iOS Tracks ‘Anything You Do on Any Website’

Users of Apple’s Instagram and Facebook iOS apps are being warned that both use an in-app browser that allows parent company Meta to track ‘every single tap’ users make with external websites acces ...

Continue Reading
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL re ...

Continue Reading

CVSS3 - MEDIUM

Top Echelon Software: WordPress Users Disclosure (/wp-json/wp/v2/users/)

Hello Team @top_echelon_software Information: Using REST API, we can see all the WordPress users/author with some of their information. Step To Reproduce: You can get user info by entering below url ...

Continue Reading
mofh Vulnerable to Improper Restriction of XML External Entity Reference

The `xml.etree.ElementTree` module that mofh used up until version `1.0.1` implements a simple and efficient API for parsing and creating XML data. But it makes the application vulnerable to: - [Billi ...

Continue Reading
@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.Read More ...

Continue Reading
@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: