Improper Privilege Management

microweber/microweber is vulnerable to Improper Privilege Management . The vulnerability exists due lack of authorization checks in the `apiResource` parameter of `api.php` which allows an attacker to ...

Continue Reading

CVSS3 - HIGH

EulerOS Virtualization 3.0.2.0 : libvirt (EulerOS-SA-2023-1687)

According to the versions of the libvirt packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities : - A use-after-free flaw was fou ...

Continue Reading

CVSS3 - MEDIUM

Improper Authorization

modoboa is vulnerable to Improper Authorization. The vulnerability exists due to missing authorization checks on the `/api/v2/parameters/core/` API endpoint which allows an attacker to gain sensitive ...

Continue Reading

CVSS3 - CRITICAL

Threat Roundup for April 28 to May 5

![Threat Roundup for April 28 to May 5](https://blog.talosintelligence.com/content/images/2023/05/threat-roundup.jpg) Today, Talos is publishing a glimpse into the most prevalent threats we've observe ...

Continue Reading
Bullied by Bugcrowd over Kape CyberGhost disclosure

![](https://www.pentestpartners.com/content/uploads/2021/05/cyber-toast-headline.png) ### TL;DR The CyberGhost VPN client suffers from an elevation of privilege vulnerability and is filed under [CVE-2 ...

Continue Reading
Cross Site Scripting in OpenTSDB

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the bro ...

Continue Reading
Command injection in OpenTSDB

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host ...

Continue Reading
Command injection in OpenTSDB

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: