CVE-2023-34420

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web...Read More ...

Continue Reading
New tool to secure your GitHub Actions

We are excited to release a public beta of [actions-permissions](), a tool which monitors your GitHub Actions workflows and recommends the minimum permissions required to run them. Every GitHub workfl ...

Continue Reading
Azure Apache Ambari 2302250400 – Spoofing Exploit

Post ContentRead More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

MOVEit SQL Injection Exploit

This Metasploit module exploits an SQL injection vulnerability in the MOVEit Transfer web application that allows an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit Remote Code Execution Vulnerability

Post ContentRead More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

How Generative AI Can Dupe SaaS Authentication Protocols — And Effective Ways To Prevent Other Key AI Risks in SaaS

[![Generative AI](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Security and IT teams are routinely forced to adopt software be ...

Continue Reading
Moderate: libvirt security update

The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management o ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

CVE-2023-36663

it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: