Security Bulletin: Due to use of IBM WebSphere Application Server Liberty, IBM Tivoli Application Dependency Discovery Manager is vulnerable to denial of service and disclosure of sensitive information.

Summary IBM WebSphere Application Server Liberty is used by IBM Tivoli Application Dependency Discovery Manager (CVE-2023-44487 and CVE-2023-44483) Vulnerability Details ** CVEID: CVE-2023-44487 DESC ...

Continue Reading
Grocy <= 4.0.2 – CSRF Vulnerability

...Read More ...

Continue Reading
Mirth Connect 4.4.0 Remote Command Execution Exploit

A vulnerability exists within Mirth Connect due to its mishandling of deserialized data. This vulnerability can be leveraged by an attacker using a crafted HTTP request to execute OS commands within t ...

Continue Reading
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

Introduction This write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tes ...

Continue Reading
@lobehub/chat vulnerable to unauthorized access to plugins

Description: When the application is password-protected (deployed with the ACCESS_CODE option), it is possible to access plugins without proper authorization (without password). Proof-of-Concept: Let� ...

Continue Reading
firefox security update

[115.7.0.1.0.1] - Update to 115.7.0 build 1 [115.6.0-1.0.1] - Update to 115.6.0 build1 - Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file [115.5.0-1.0.1] - Update to 115.5 ...

Continue Reading
Mirth Connect 4.4.0 Remote Command Execution

...Read More ...

Continue Reading
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploi ...

Continue Reading

Back to Main

Subscribe for the latest news: