Exploit for CVE-2024-23897

Proof of Concept for Exploiting CVE-2024-23897 Vulnerability in Jenkins Versions 2.441 and Earlier This repository provides a proof-of-concept (PoC) exploit for the CVE-2024-23897 vulnerability affect ...

Continue Reading
Secure Your APIs and Reduce Your Attack Surface With Modern, AI-powered API Security in Qualys Web Application Scanning (WAS)

The rise of APIs presents both opportunities and challenges in today’s hyperconnected digital world. APIs are integral to digital transformation initiatives across industries. The latest data indica ...

Continue Reading
Exploit for Signal Handler Race Condition in Openbsd Openssh

转载原文 CVE-2024-6387 - PoC 📜 Description Note: This script is a quick prototype PoC, expect some errors and bugs may occur. Tested on: Kali Linux, ParrotSec, Ubuntu 22.04 Remote ...

Continue Reading
phpCAS vulnerability

Releases Ubuntu 22.04 LTS Ubuntu 20.04 LTS Packages php-cas - Central Authentication Service client library in php Details Filip Hejsek discovered that phpCAS was using HTTP headers to determine t ...

Continue Reading
CVE-2024-41110 Moby authz zero length regression

Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass ...

Continue Reading
TracFone will pay $16 million to settle FCC data breach investigation

Following three separate data breaches between 2021 and 2023 which exposed the proprietary information (PI) of TracFone Wireless customers, the Federal Communications Commission (FCC) announced that t ...

Continue Reading
CVE-2024-7079 Openshift-console: unauthenticated installation of helm charts

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this en ...

Continue Reading
CVE-2024-6874 macidn punycode buffer overread

libcurl's URL API function curl_url_get() offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer ...

Continue Reading

Back to Main

Subscribe for the latest news: