Bypass IP detection to brute-force password in Microweber

In the login API, an IP address will by default be blocked when the user tries to login incorrectly more than 5 times. However, a bypass to this mechanism is possible by abusing a X-Forwarded-For head ...

Continue Reading
It’s the Summer of AppSec: Q2 Improvements to Our Industry-Leading DAST and WAAP

![It’s the Summer of AppSec: Q2 Improvements to Our Industry-Leading DAST and WAAP](https://blog.rapid7.com/content/images/2022/07/summer-of-appsec.jpg) Summer is in full swing, and that means soarin ...

Continue Reading
CVE-2022-31105

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation ...

Continue Reading
CVE-2022-31102

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow a ...

Continue Reading
KB5015809: Windows 10 version 17784 / Azure Stack HCI Security Update (July 2022)

The remote Windows host is missing security update 5015809. It is, therefore, affected by miscellaneous security issues with the functionality of the internal OS.Read More ...

Continue Reading
KB5015875: Windows Server 2012 Security Update (July 2022)

The remote Windows host is missing security update 5015875 or cumulative update 5015863. It is, therefore, affected by multiple vulnerabilities: - A remote code execution vulnerability. An attacker ...

Continue Reading
KB5015862: Windows Server 2008 R2 Security Update (July 2022)

The remote Windows host is missing security update 5015862 or cumulative update 5015866. It is, therefore, affected by multiple vulnerabilities: - A remote code execution vulnerability. An attacker ...

Continue Reading
KB5015807: Windows 10 Version 20H2 / Windows 10 Version 21H1 / Windows 10 Version 21H2 Security Update (July 2022)

The remote Windows host is missing security update 5015807. It is, therefore, affected by multiple vulnerabilities: - A remote code execution vulnerability. An attacker can exploit this to bypas ...

Continue Reading

Back to Main

Subscribe for the latest news: