CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via...Read More ...

Continue Reading
CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via...Read More ...

Continue Reading
CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via...Read More ...

Continue Reading
Pomerium service account access token may grant unintended access to databroker API in github.com/pomerium/pomerium

Pomerium service account access token may grant unintended access to databroker API in...Read More ...

Continue Reading
open-webui Insecure Direct Object Reference (IDOR) vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint https://0.0.0.0:3000/api/v1/memories/{id}/update, w ...

Continue Reading
open-webui allows writing and deleting arbitrary files

In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vuln ...

Continue Reading
K000141403: Apache Tomcat vulnerability CVE-2024-38286

Security Advisory Description The cve record for the cve id does not exist. (CVE-2024-38286) Impact There is no impact; F5 products are not affected by this...Read More ...

Continue Reading
CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, citing ev ...

Continue Reading

Back to Main

Subscribe for the latest news: