Oracle Linux 9 : openssl (ELSA-2024-0310)

The remote Oracle Linux 9 host has packages installed that are affected by a vulnerability as referenced in the ELSA-2024-0310 advisory. Issue summary: A bug has been identified in the processing of ...

Continue Reading
PRTG Authenticated Remote Code Execution Exploit

...Read More ...

Continue Reading
Getwid – Gutenberg Blocks < 2.0.5 – Missing Authorization to Recaptcha API Key Modification

Description The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This m ...

Continue Reading
Missing Authorization

changedetection_io is vulnerable to Missing Authorization. The vulnerability is due to a missing annotation @auth.check_token on the WatchHistory API endpoint /api/v1/watch//history. This can allows a ...

Continue Reading
Information Exposure

Dependency-Check Core is vulnerable to Information Exposure Through Log Files. The vulnerability is due to the logging of sensitive information when in debug mode. An attacker with access to debug log ...

Continue Reading
CVE-2024-23633

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. Prior to vers ...

Continue Reading
CVE-2024-23453

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. Th ...

Continue Reading
Exploit for Weak Password Recovery Mechanism for Forgotten Password in Gitlab

Giới thiệu GitLab là trình quản lý kho dữ liệu lưu trữ trên web được áp dụng rộng rãi, cung cấp nền tảng toàn diện để quản lý mã nguồn, tích hợp, duy t ...

Continue Reading

Back to Main

Subscribe for the latest news: