LibreNMS vulnerable to Stored Cross-site Scripting via File Upload

Summary Stored Cross-Site Scripting (XSS) can archive via Uploading a new Background for a Custom Map. Details Users with "admin" role can set background for a custom map, this allow ...

Continue Reading
LibreNMS vulnerable to Stored Cross-site Scripting via File Upload

Summary Stored Cross-Site Scripting (XSS) can archive via Uploading a new Background for a Custom Map. Details Users with "admin" role can set background for a custom map, this allow ...

Continue Reading
CVE-2024-9194 SQL Injection in the Octopus Server REST API

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This i ...

Continue Reading
CVE-2024-9194 SQL Injection in the Octopus Server REST API

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This i ...

Continue Reading
CVE-2024-9358 ThingsBoard HTTP RPC API resource consumption

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP RPC API. The manipulation lead ...

Continue Reading
CVE-2024-9358 ThingsBoard HTTP RPC API resource consumption

A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP RPC API. The manipulation lead ...

Continue Reading
CVE-2024-8675 Soumettre.fr <= 2.1.2 – Missing Authorization

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and inclu ...

Continue Reading
CVE-2024-8675 Soumettre.fr <= 2.1.2 – Missing Authorization

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and inclu ...

Continue Reading

Back to Main

Subscribe for the latest news: