A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may ...
Continue ReadingJuly 17, 2023
A local privilege escalation (LPE) vulnerability in Windows was ...Read More ...
Continue ReadingJuly 16, 2023
[]() With generative artificial intelligence (AI) becoming all the rage th ...
Continue ReadingJuly 15, 2023
[]() Microsoft on Friday said a validation error in its source code allo ...
Continue ReadingJuly 15, 2023
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.Read More ...
Continue ReadingJuly 15, 2023
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file o ...
Continue ReadingJuly 15, 2023
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.Rea ...
Continue ReadingJuly 14, 2023
Back to Main