CVE-2024-20255

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS ...

Continue Reading
Security Bulletin: IBM PowerVM Novalink is vulnerable because Apache Santuario could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of a private key in the log files.(CVE-2023-44483)

Summary IBM PowerVM Novalink is vulnerable because Apache Santuario could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of a private key in the log files ...

Continue Reading
CVE-2024-24771

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their crede ...

Continue Reading
CVE-2024-24815

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0- ...

Continue Reading
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

Affected packages The vulnerability has been discovered in the core HTML parsing module and may affect all editor instances that: * Enabled full-page editing mode, * or enabled CDATA elements in Advan ...

Continue Reading
Digital Experience Monitoring | What Is DEM?

Introduction to Digital Experience Monitoring: Illuminating the Basics In an era governed by technology, the satisfaction of an end-user is of utmost importance. It has the power to stimulate or to ha ...

Continue Reading
Amazon Linux AMI : libtiff (ALAS-2024-1913)

The version of libtiff installed on the remote host is prior to 4.0.3-35.50. It is, therefore, affected by a vulnerability as referenced in the ALAS-2024-1913 advisory. An out-of-memory flaw was foun ...

Continue Reading
Amazon Linux 2 : cri-tools (ALAS-2024-2446)

The version of cri-tools installed on the remote host is prior to 1.29.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2-2024-2446 advisory. A malicious HTTP sen ...

Continue Reading

Back to Main

Subscribe for the latest news: