CVE-2024-45591 XWiki Platform document history including authors of any page exposed to unauthorized actors

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the pag ...

Continue Reading
CVE-2024-45596 Directus’s session is cached for OpenID and OAuth2 if `redirect` is not used

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication ...

Continue Reading
CVE-2024-38257 Microsoft AllJoyn API Information Disclosure Vulnerability

...Read More ...

Continue Reading
CVE-2024-45596 Directus’s session is cached for OpenID and OAuth2 if `redirect` is not used

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication ...

Continue Reading
CVE-2024-45596 Directus’s session is cached for OpenID and OAuth2 if `redirect` is not used

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication ...

Continue Reading
CVE-2024-45596

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication ...

Continue Reading
Microsoft AllJoyn API Information Disclosure Vulnerability

...Read More ...

Continue Reading
Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Sqlpad

SQLPad RCE Exploit This repository contains an exploit script for CVE-2022-0944 in SQLPad, a vulnerability that allows for Remote Code Execution (RCE) via the /api/test-connection endpoint. Overview T ...

Continue Reading

Back to Main

Subscribe for the latest news: