Exploit for CVE-2023-2732

# CVE-2023-2732 ### MStore API <= 3.9.2 - Authentication By...Read More ...

Continue Reading
CVE-2023-2886

Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.Read Mo ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

GUAC 0.1 Beta: Google’s Breakthrough Framework for Secure Software Supply Chains

[![Google](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Google on Wednesday announced the **0.1 Beta version** of [GUAC]() (sh ...

Continue Reading
CVE-2023-2734

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart ...

Continue Reading
CVE-2023-2733

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupo ...

Continue Reading
CVE-2023-2732

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add l ...

Continue Reading
Timing Attack

github.com/ginuerzh/gost is vulnerable to Timing Attacks. The vulnerability exists because the `Authenticate` function of `auth.go` does not properly compare sensitive secrets such as passwords, token ...

Continue Reading
Ingress-nginx `path` sanitization can be bypassed with newline character

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` f ...

Continue Reading

Back to Main

Subscribe for the latest news: