CVE-2023-0326

An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.Read More ...

Continue Reading
CVE-2023-28102

discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` file unsafely constructs a shell string using the file parameter, which can pote ...

Continue Reading
Apiman vulnerable to permissions bypass due to missing check on API key URL

### Impact Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess t ...

Continue Reading
CVE-2023-28640

Apiman is a flexible and open source API Management platform. Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they d ...

Continue Reading
Apiman vulnerable to permissions bypass due to missing check on API key URL

### Impact Due to a missing permissions check, an attacker with an authenticated Apiman Manager account may be able to gain access to API keys they do not have permission for if they correctly guess t ...

Continue Reading
FortiOS FortiProxy FortiSwitchManager v7.2.1 – Authentication Bypass Vulnerability

Post ContentRead More ...

Continue Reading

CVSS3 - CRITICAL

Sysax Multi Server 6.95 – (Password) Denial of Service Exploit

Post ContentRead More ...

Continue Reading
TensorFlow Denial of Service vulnerability

### Impact A malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. To minimize the bug, we built a simple single-layer TensorFlow mod ...

Continue Reading

Back to Main

Subscribe for the latest news: