CVE-2023-28434

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket w ...

Continue Reading
OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

[![ChatGPT](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() OpenAI on Friday disclosed that a bug in the Redis open source librar ...

Continue Reading
Exploit for CVE-2023-23752

# CVE-2023-23752 Joomla Unauthorized Access Vulnerability (CVE-2...Read More ...

Continue Reading

CVSS3 - MEDIUM

CVE-2023-28150

An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.Read More ...

Continue Reading
Interactive `run` permission prompt spoofing via improper ANSI neutralization

### Summary Arbitrary program names without any ANSI filtering allows any malicious program to clear the first 2 lines of a `op_spawn_child` or `op_kill` prompt and replace it with any desired text. # ...

Continue Reading
CVE-2023-28151

An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.Read More ...

Continue Reading
Threat Roundup for March 17 to March 24

![Threat Roundup for March 17 to March 24](https://blog.talosintelligence.com/content/images/2023/03/threat-roundup-2.jpg) Today, Talos is publishing a glimpse into the most prevalent threats we've ob ...

Continue Reading
Tenable Sensor Proxy < 1.0.7 Multiple Vulnerabilities (TNS-2023-15)

According to its self-reported version, the Tenable Sensor Proxy application running on the remote host is version 1.0.6. It is, therefore, affected by multiple vulnerabilities in OpenSSL prior to ver ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: