CVE-2022-38152

An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in ...

Continue Reading
Exploit for Path Traversal in Secureauth Impacket

Impacket ======== [![Latest Version](https://img.shields.io/pyp...Read More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-36600

BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or ...

Continue Reading
When disclosure goes wrong. People

![](https://www.pentestpartners.com/content/uploads/2020/08/disclosurepeople-headline.png) My experience of vulnerability disclosure is that it is rarely as easy or simple as it could be. I had hoped ...

Continue Reading
Exploit for Code Injection in Combodo Itop

# iTop RCE via SSTI - CVE-2022-24780 exploit > iTop Read More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2022-38152

An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in ...

Continue Reading
JVN#76024879: PowerCMS XMLRPC API vulnerable to command injection

PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability ([CWE-74]()). Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Per ...

Continue Reading
elrond-go MultiESDTNFTTransfer call on a SC address with missing function name

### Impact Anyone who uses elrond-go to process blocks (historical or actual) that contains a transaction like this: `MultiESDTNFTTransfer@01@54444558544b4b5955532d323631626138@00@0793afc18c8da2ca@` ( ...

Continue Reading

Back to Main

Subscribe for the latest news: