CVE-2024-21583

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gh ...

Continue Reading
CVE-2024-21583

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gh ...

Continue Reading
CVE-2024-21583

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gh ...

Continue Reading
CVE-2024-29885

silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any user who has access to view the repor ...

Continue Reading
Exploit for CVE-2023-22515

CVE-2023-22515-NSE Vulnerability checking tool via Nmap Scripting Engine 1. Познакомиться и описать принципы (механизмы) работы уязвимости CVE-202 ...

Continue Reading
1Panel has an SQL injection issue related to the orderBy clause

There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The proof is as...Read More ...

Continue Reading
Information Disclosure

sylius/sylius is vulnerable to Information Disclosure. The vulnerability is due to the /api/v2/shop/adjustments/{id} endpoint, which allows an attacker to enumerate valid adjustment IDs to retrieve or ...

Continue Reading
Time-of-check Time-of-use (TOCTOU) Race Condition

Apache streampipes is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition. The vulnerability arises from insufficient synchronization during user registration, allowing multiple simultaneo ...

Continue Reading

Back to Main

Subscribe for the latest news: