mofh Vulnerable to Improper Restriction of XML External Entity Reference

The `xml.etree.ElementTree` module that mofh used up until version `1.0.1` implements a simple and efficient API for parsing and creating XML data. But it makes the application vulnerable to: - [Billi ...

Continue Reading
Hackers Behind Cuba Ransomware Attacks Using New RAT Malware

[![Cuba Ransomware](https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEjG5NY6z_E3mIqws1GTNFoFKEavt9jBxtciK10htSDSQc_JECqfwKvNTPymBW0axc6McWFzM08_t78ovmJx91jcYFgquWC09fNYVXBMKenTKS08JGIU8VnHvwXE ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

OpenTIP, command line edition

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2021/11/26093821/abstract_digits_cell-990x400.jpg) For more than a year, we have been providing free intelligence services via [th ...

Continue Reading
Cross Site Scripting (XSS)

LocalStack is vulnerable to cross-site scripting. The vulnerability is due to not having CSRF protection. An attacker can trick a user into visiting a website with malicious Javascript code, which que ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2022-36923

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104 ...

Continue Reading
CVE-2022-34365

WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, ...

Continue Reading
Wallarm at Black Hat USA 2022

Black Hat USA is celebrating its 25th anniversary, and Wallarm will be on hand for the festivities. If you’re headed to Vegas this year, we invite you to meet our crew and talk about API security. ** ...

Continue Reading
Splunk Enterprise 8.1.x < 8.1.7 Information Disclosure

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to return ver ...

Continue Reading

Back to Main

Subscribe for the latest news: