Information Disclosure

github.com/usememos/memos is vulnerable to information disclosure. A remote authenticated attacker is able to gain access to confidential user details via the `api/status` endpoint, which returns emai ...

Continue Reading
Insecure Direct Object References(IDOR)

github.com/usememos/memos is vulnerable to insecure direct object references. Improper Authorization due to insecure direct object references allow an attacker to trigger the `Reset` API on user's beh ...

Continue Reading
Improper Authentication

github.com/usememos/memos is vulnerable to improper authentication. The vulnerability allows a remote attacker to use the `Reset` API on any user without consent via IDOR.Read More ...

Continue Reading

CVSS3 - CRITICAL

Cross-Site Request Forgery (CSRF)

github.com/usememos/memos is vulnerable to cross-site request forgery. An attacker is able to add new members, via `user` API by exploiting the CSRF issue.Read More ...

Continue Reading
Cross-Site Request Forgery (CSRF)

github.com/usememos/memos is vulnerable to cross-site request forgery. The vulnerability exists in an incorrectly specified destination in a communication channel which allows an attacker to change th ...

Continue Reading
Cross-Site Request Forgery (CSRF)

github.com/usememos/memos is vulnerable to cross-site request forgery. An attacker is able to force the change of a password and/or other personal information on a user's behalf, through `shortcut` AP ...

Continue Reading
CVE-2022-38723

Gravitee API Management before 3.15.13 allows path traversal through HTML injection.Read More ...

Continue Reading
Security Bulletin: IBM InfoSphere Information Server is affected by an information disclosure vulnerability in Kubernetes (CVE-2021-25740)

## Summary An information disclosure vulnerability in Kubernetes used by IBM InfoSphere Information Server was addressed. ## Vulnerability Details ** CVEID: **[CVE-2021-25740]() ** DESCRIPTION: **Kube ...

Continue Reading

CVSS3 - LOW

CVSS2 - LOW

Back to Main

Subscribe for the latest news: