CVE-2023-33466

Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite t ...

Continue Reading
​Ovarro TBox RTUs

## 1. EXECUTIVE SUMMARY * **​CVSS v3 7.2** * **​ATTENTION:** Exploitable remotely/low attack complexity * **​Vendor: **Ovarro * **​Equipment: **TBox RTUs * **​Vulner ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 19, 2023 to June 25, 2023)

Last week, there were 84 vulnerabilities disclosed in 76 WordPress Plugins and 2 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 42 Vulnerabi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Fluhorse: Flutter-Based Android Malware Targets Credit Cards and 2FA Codes

[![Android Malware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Cybersecurity researchers have shared the inner workings of a ...

Continue Reading
Improper Privilege Management

streampipes-rest is vulnerable to Improper Privilege Management. The vulnerability exists due to improperly validating admin-only access in `UserResource.java`, which allows an attacker to elevate pri ...

Continue Reading
Missing Authorization

github.com/mattermost/mattermost-server is vulnerable to Missing Authorization. The vulnerability exists because the library fails to validate all parameters, allowing an authenticated attacker to edi ...

Continue Reading
Missing Authorization

github.com/mattermost/mattermost-server is vulnerable to Missing Authorization. The vulnerability exists because the library does not verify whether the requestor is a system admin or not before allow ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Missing Authorization

github.com/mattermost/mattermost is vulnerable to Missing Authorization. A remote authenticated attacker is able to gain access to arbitrary posts by using the message threads API because the library ...

Continue Reading

Back to Main

Subscribe for the latest news: