Adlisting Classified Ads 2.14.0 – WebPage Content Information Disclosure

Post ContentRead More ...

Continue Reading
Privilege escalation via ApiTokensEndpoint

### Impact An attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with greater scopes, and use those token ...

Continue Reading
Privilege escalation via ApiTokensEndpoint

### Impact An attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with greater scopes, and use those token ...

Continue Reading
Security Bulletin: Multiple vulnerabilities present in IBM Answer Retrieval for Watson Discovery versions 2.12 and earlier

## Summary This fix upgrades to node 18.16.1. ## Vulnerability Details ** CVEID: **[CVE-2023-30584]() ** DESCRIPTION: **Node.js could allow a remote attacker to bypass security restrictions, caused by ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-21627

Memory corruption in Trusted Execution Environment while calling service API with invalid address.Read More ...

Continue Reading
CVE-2023-4009

In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges ...

Continue Reading
CVE-2023-37486

Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On suc ...

Continue Reading
(RHSA-2023:4335) Important: Security Update for cert-manager Operator for Red Hat OpenShift 1.10.3

The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it pos ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: