WatchGuard FireboxV Fireware OS Web Detection

The web UI for a WatchGuard FireboxV running Fireware OS was detected on the remote host. Note the plugin attempts to retrieve the Fireware OS version information from the API when HTTP Basic authenti ...

Continue Reading
apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page

### Impact The default landing page contained HTML to display a sample `curl` command which is made visible if the full landing page bundle could not be fetched from Apollo's CDN. The server's URL is ...

Continue Reading
CVE in KubeVirt – arbitrary host file read from the VM

**Summary** As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of path sanitization which leads to a path traversal was identified. Google tested the exploitabil ...

Continue Reading
Nodejs ‘undici’ Vulnerable to CRLF Injection via Content-Type

### Impact `=Read More ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-36024

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2022-1798

An arbitrary file read vulnerability was found in the kubeVirt API. This flaw makes it possible to use the kubeVirt API to provide access to host files (like /etc/passwd, for example) in a KubeVirt VM ...

Continue Reading
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution

### Impact py-cord is a an API wrapper for Discord written in Python. Bots using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` ...

Continue Reading
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution

### Impact py-cord is a an API wrapper for Discord written in Python. Bots using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` ...

Continue Reading

Back to Main

Subscribe for the latest news: