The remote Oracle Linux 9 host has packages installed that are affected by a vulnerability as referenced in the ELSA-2024-0310 advisory. Issue summary: A bug has been identified in the processing of ...
Continue ReadingJanuary 24, 2024
Description The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the recaptcha_api_key_manage function in all versions up to, and including, 2.0.3. This m ...
Continue ReadingJanuary 24, 2024
changedetection_io is vulnerable to Missing Authorization. The vulnerability is due to a missing annotation @auth.check_token on the WatchHistory API endpoint /api/v1/watch//history. This can allows a ...
Continue ReadingJanuary 24, 2024
Dependency-Check Core is vulnerable to Information Exposure Through Log Files. The vulnerability is due to the logging of sensitive information when in debug mode. An attacker with access to debug log ...
Continue ReadingJanuary 24, 2024
Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. Prior to vers ...
Continue ReadingJanuary 24, 2024
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. Th ...
Continue ReadingJanuary 24, 2024
Giới thiệu GitLab là trình quản lý kho dữ liệu lưu trữ trên web được áp dụng rộng rãi, cung cấp nền tảng toàn diện để quản lý mã nguồn, tích hợp, duy t ...
Continue ReadingJanuary 24, 2024
Back to Main