CVE-2024-6557 SchedulePress <= 5.1.3 – Unauthenticated Full Path Disclosure

The SchedulePress – Auto Post &amp; Publish, Auto Social Share, Schedule Posts with Editorial Calendar &amp; Missed Schedule Post Publisher plugin for WordPress is vulnerable to Full Path Di ...

Continue Reading
Malicious code in discord-api-ts (npm)

-= Per source details. Do not edit below this line.=- Source: ghsa-malware (0a3626a3ca7ff0b0aad0d6f253348feea62a16670319bc0de2e18d56a656279b) Any computer that has this package installed or running sh ...

Continue Reading
SQL Injection

github.com/openclarity/kubeclarity is vulnerable to SQL Injection. The vulnerability is due to manipulating the packageID parameter in the /api/applicationResources endpoint, where the fmt.Sprintf fun ...

Continue Reading
ghostscript vulnerabilities

It was discovered that Ghostscript incorrectly handled certain long PDF filter names. An attacker could possibly use this issue to cause Ghostscript to crash, resulting in a denial of service. This is ...

Continue Reading
Updated nss & firefox packages fix security vulnerabilities

Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in NSS. (CVE-2024-6602) Memory corruption in thread creation. (CVE-2024-6603) ...

Continue Reading
JeecgBoot JimuReport – Template injection

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manip ...

Continue Reading
Ubuntu 20.04 LTS / 22.04 LTS / 24.04 LTS : Ghostscript vulnerabilities (USN-6897-1)

The remote Ubuntu 20.04 LTS / 22.04 LTS / 24.04 LTS host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-6897-1 advisory. It was discovered that Ghostscri ...

Continue Reading
ZITADEL Go’s GRPC example code vulnerability – GO-2024-2687 HTTP/2 CONTINUATION flood in net/http

Summary Applications using the zitadel-go v3 library (next branch) might be impacted by package vulnerabilities. The output of govulncheck suggests that only example code seems to be impacted, based o ...

Continue Reading

Back to Main

Subscribe for the latest news: