Information Disclosure

org.owasp/dependency-check is vulnerable to Information Disclosure. The vulnerability is due to the nvdApiKey not being masked because it doesn't match the specified patterns. As a result, when d ...

Continue Reading
External Control Of File Name Or Path

h2o is vulnerable to External Control of File Name or Path. The vulnerability exists due to improper input validation which allows an attacker to manipulate file paths to access or modify files outsid ...

Continue Reading
The Do?s and Don?ts of Modern API Security

...Read More ...

Continue Reading
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: ...Read More ...

Continue Reading
CVE-2023-6910

A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no ...

Continue Reading
Exploit for Server-Side Request Forgery in Rbaskets Request Baskets

basketcraft this is a script that exploits the CVE-2023-27163 vulnerability which is an SSRF in the request-baskets version 1.2.1 SSRF on Request-Baskets (CVE-2023–27163) CVE-2023–27163 represents ...

Continue Reading
Exploit for Server-Side Request Forgery in Rbaskets Request Baskets

basketcraft this is a script that exploits the CVE-2023-27163 vulnerability which is an SSRF in the request-baskets version 1.2.1 SSRF on Request-Baskets (CVE-2023–27163) CVE-2023–27163 represents ...

Continue Reading
Exploit for Server-Side Request Forgery in Rbaskets Request Baskets

basketcraft this is a script that exploits the CVE-2023-27163 vulnerability which is an SSRF in the request-baskets version 1.2.1 SSRF on Request-Baskets (CVE-2023–27163) CVE-2023–27163 represents ...

Continue Reading

Back to Main

Subscribe for the latest news: