CVE-2024-42362 GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/import

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in...Read More ...

Continue Reading
CVE-2024-8023 chillzhuang SpringBlade list sql injection

A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql ...

Continue Reading
KubePi may allow unauthorized access to system API in github.com/KubeOperator/kubepi

KubePi may allow unauthorized access to system API in...Read More ...

Continue Reading
KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys in github.com/KubeOperator/kubepi

KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys in...Read More ...

Continue Reading
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections in github.com/hashicorp/consul

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections in...Read More ...

Continue Reading
Argo CD authenticated but unauthorized users may enumerate Application names via the API in github.com/argoproj/argo-cd

Argo CD authenticated but unauthorized users may enumerate Application names via the API in...Read More ...

Continue Reading
HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul

HashiCorp Consul Cross-site Scripting vulnerability in...Read More ...

Continue Reading
Dapr API token authentication bypass in HTTP endpoints in github.com/dapr/dapr

Dapr API token authentication bypass in HTTP endpoints in...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: