Exploit for CVE-2024-4898

CVE-2024-4898-Poc CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrati ...

Continue Reading
CVE-2024-29025 vulnerabilities

Vulnerabilities for packages: opensearch, management-api-for-apache-cassandra, cloudwatch-exporter, selenium, wavefront-proxy, neo4j, spark,...Read More ...

Continue Reading
GHSA-5JPM-X58V-624V vulnerabilities

Vulnerabilities for packages: opensearch, management-api-for-apache-cassandra, cloudwatch-exporter, selenium, wavefront-proxy, neo4j, spark,...Read More ...

Continue Reading
CVE-2024-37307

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of cilium-bugtool ca ...

Continue Reading
CVE-2024-37152

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentica ...

Continue Reading
CVE-2024-27163 Leak of admin password and passwords

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. An attacker stealing the cookie of an adm ...

Continue Reading
CVE-2024-27168 Hardcoded keys used to generate authentication cookies

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the ...

Continue Reading
CVE-2024-27169 Lack of authentication

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/mode ...

Continue Reading

Back to Main

Subscribe for the latest news: