YAPI SQL Injection Vulnerability

YAPI is an api management platform. YAPI is vulnerable to SQL injection, which can be exploited by attackers to obtain user token and cause command execution.Read More ...

Continue Reading
Simmeth System GmbH Supplier Manager LFI / SQL Injection / Bypass Vulnerabilities

Simmeth System GmbH Supplier Manager (Lieferantenmanager) versions prior to 5.6 suffer from authentication bypass, code execution, cross site scripting, information leakage, remote SQL injection, and ...

Continue Reading
VMware NSX Manager XStream Unauthenticated Remote Code Execution Exploit

VMware Cloud Foundation (NSX-V) contains a remote code execution vulnerability via XStream open source library. VMware has evaluated the severity of this issue to be in the Critical severity range wit ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2022-20925

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying op ...

Continue Reading
CVE-2022-20926

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying op ...

Continue Reading
Foxit Reader Optional Content Group use-after-free vulnerability

# Talos Vulnerability Report ### TALOS-2022-1614 ## Foxit Reader Optional Content Group use-after-free vulnerability ##### November 10, 2022 ##### CVE Number CVE-2022-40129 ##### SUMMARY A use-after-f ...

Continue Reading
Security Updates for Microsoft .NET Framework (November 2022)

The Microsoft .NET Framework installation on the remote host is missing a security update. It is, therefore, affected by an information disclosure vulnerability in the System.Data.SqlClient and Micros ...

Continue Reading
Foxit Reader openPlayer use-after-free vulnerability

# Talos Vulnerability Report ### TALOS-2022-1602 ## Foxit Reader openPlayer use-after-free vulnerability ##### November 10, 2022 ##### CVE Number CVE-2022-37332 ##### SUMMARY A use-after-free vulnerab ...

Continue Reading

Back to Main

Subscribe for the latest news: