Security Updates for Microsoft PowerPoint Products (August 2024)

The Microsoft PowerPoint Products are missing a security update. It is, therefore, affected by the following vulnerability: A remote code execution vulnerability. An attacker can exploit this to ...

Continue Reading
Dorsett Controls InfoScan < 1.38 Multiple Vulnerabilities (July 2024)

The version of Dorsett Controls InfoScan running on the remote host is prior to 1.38. It is, therefore, affected by multiple vulnerabilities: Dorsett Controls Central Server update server has potent ...

Continue Reading
CVE-2024-23168

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code...Read More ...

Continue Reading
CVE-2024-42487 Cilium’s Gateway API route matching order contradicts specification

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes ...

Continue Reading
Gateway API route matching order contradicts specification

Impact Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Gateway API specification. In particular, request headers are matched before request methods, when the ...

Continue Reading
CVE-2024-42487

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes ...

Continue Reading
OpenMetadata 1.2.3 Authentication Bypass / SpEL Injection Exploit

This Metasploit module exploits OpenMetadata versions 1.2.3 and below by chaining an API authentication bypass using JWT tokens along with a SpEL injection vulnerability to achieve arbitrary command.. ...

Continue Reading
CVE-2024-42487 Cilium’s Gateway API route matching order contradicts specification

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes ...

Continue Reading

Back to Main

Subscribe for the latest news: