CVE-2024-40633

Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the /api/v2/shop/adjustments/{id} endpoint, which retrieves order adjustments based on incremental i ...

Continue Reading
Sylius has a security vulnerability via adjustments API endpoint

Impact A security vulnerability was discovered in the /api/v2/shop/adjustments/{id} endpoint, which retrieves order adjustments based on incremental integer IDs. The vulnerability allows an attacker t ...

Continue Reading
Security Bulletin: IBM MaaS360 Cloud Extender VPN Module affected by vulnerability (CVE-2024-4741)

Summary Vulnerability contained within OpenSSL (a 3rd party component) was addressed in the IBM MaaS360 VPN Module. Vulnerability Details ** CVEID: CVE-2024-4741 DESCRIPTION: **OpenSSL could allow a ...

Continue Reading
CVE-2024-20419

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including adminis ...

Continue Reading
CVE-2024-5703 Icegram Express – Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 – Missing Authorization

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress &amp; WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing ...

Continue Reading
age Plugins

age is a file encryption tool, library, and format. It lets you encrypt files to &quot;recipients&quot; and decrypt them with &quot;identities&quot;. $ age-keygen -o key.txt Public key ...

Continue Reading
CVE-2024-6834 Imperative Local Command Injection allows Activity Masking

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints req ...

Continue Reading
CVE-2024-6834

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints req ...

Continue Reading

Back to Main

Subscribe for the latest news: