Anti Hacker < 4.35 – Cross-Site Request Forgery via antihacker_ajax_scan

Description The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.35 ( ...

Continue Reading
LA-Studio Element Kit for Elementor < 1.1.6 – Missing Authorization

Description The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a REST-API endpoint in versions up to, ...

Continue Reading
Exploit for Server-Side Request Forgery in Rbaskets Request Baskets

CVE-2023-27163 [!WARNING] This is an educational project, I am not responsible for any use Exploit Exploit for CVE-2023-27163, an SSRF vulnerability discovered in request-baskets in all versions bel ...

Continue Reading
CVE-2023-50711

vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starting in version 0.5.0 and prior to version 0.12.0, an issue in the FamStructWrappe ...

Continue Reading
Three Ways To Supercharge Your Software Supply Chain Security

Section four of the &quot;Executive Order on Improving the Nation's Cybersecurity&quot; introduced a lot of people in tech to the concept of a &quot;Software Supply Chain&quot; an ...

Continue Reading
Improper Authorization

github.com/mattermost/mattermost is vulnerable to Improper Authorization. The vulnerability is caused due to improper permission validation while a user views archived public channels. One member of a ...

Continue Reading
Improper Authorization

github.com/mattermost/mattermost is vulnerable to Improper Authorization. The vulnerability is caused due to improper permission validation while a user views archived public channels. One member of a ...

Continue Reading
Mattermost viewing archived public channels permissions vulnerability

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via ...

Continue Reading

Back to Main

Subscribe for the latest news: