Ubuntu 16.04 ESM / 18.04 ESM / 20.04 ESM / 22.04 ESM : GNU SASL vulnerability (USN-6169-1)

The remote Ubuntu 16.04 ESM / 18.04 ESM / 20.04 ESM / 22.04 ESM host has packages installed that are affected by a vulnerability as referenced in the USN-6169-1 advisory. - GNU SASL libgsasl server- ...

Continue Reading
Access Control Bypass

github.com/grafana/grafana is vulnerable to Access Control Bypass. The vulnerability exists due to a lack of write authorization checks in `authorization.go`, which allows an attacker with the viewer ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-34242

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when Gateway API is enabled in Cilium, the absence of a check on the namespace in wh ...

Continue Reading
Denial Of Service (DoS)

github.com/grafana/grafana is vulnerable to Denial Of Service (DoS). The vulnerability exists due to executing concurrent mixed queries through the `executeConcurrentQueries` function of `query.go`, w ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

CVE-2023-35809

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the REST API. By using a crafted request, custom PHP code ...

Continue Reading
MStore API < 3.9.8 – Unauthenticated Blind SQLi

The plugin does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owne ...

Continue Reading
MStore API < 3.9.9 – Unauthenticated Privilege Escalation

The plugin does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plug ...

Continue Reading
Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive Disruptions

[![Massive DDoS Attack](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft on Friday attributed a string of service outage ...

Continue Reading

Back to Main

Subscribe for the latest news: