Code injection

An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API...Read More ...

Continue Reading
Design/Logic Flaw

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the / ...

Continue Reading
Cross site scripting

Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, eve ...

Continue Reading
Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

Fortinet has disclosed a new critical security flaw in FortiOS SSL VPN that it said is likely being exploited in the wild. The vulnerability, CVE-2024-21762 (CVSS score: 9.6), allows for the execution ...

Continue Reading
EulerOS 2.0 SP5 : tomcat (EulerOS-SA-2024-1166)

According to the versions of the tomcat packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : Incomplete Cleanup vulnerability in Apache Tomca ...

Continue Reading
EulerOS 2.0 SP5 : curl (EulerOS-SA-2024-1136)

According to the versions of the curl packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities : This flaw allows an attacker to insert cookies at ...

Continue Reading
CentOS 8 : firefox (CESA-2023:1787)

The remote CentOS Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the CESA-2023:1787 advisory. Unexpected data returned from the Safe Browsing API ...

Continue Reading
CentOS 8 : firefox (CESA-2023:7508)

The remote CentOS Linux 8 host has a package installed that is affected by multiple vulnerabilities as referenced in the CESA-2023:7508 advisory. On some systemsdepending on the graphics settings an ...

Continue Reading

Back to Main

Subscribe for the latest news: