Modoboa < 2.1.0 – Improper Authorization

Improper Authorization in GitHub repository modoboa/modoboa prior to...Read More ...

Continue Reading
CVE-2024-4183

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the ser ...

Continue Reading
CVE-2024-32046

Mattermost versions 9.6.x &lt;= 9.6.0, 9.5.x &lt;= 9.5.2, 9.4.x &lt;= 9.4.4 and 8.1.x &lt;= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is ...

Continue Reading
CVE-2024-33669

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows a ...

Continue Reading
CVE-2024-33670

Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as Jav ...

Continue Reading
CVE-2024-33666

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to...R ...

Continue Reading
Security Bulletin: IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to information disclosure in Kubernetes [CVE-2021-25740]

Summary IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to information disclosure in Kubernetes, caused by a confused deputy attack. [CVE-2021-25740]. Kubernetes is inclu ...

Continue Reading
SQL Injection

umbraco is vulnerable to SQL injection. The vulnerability is due to insufficient input validation in API endpoint handling, that allows attackers to inject SQL code through modified...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: