CVE-2022-2531

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Qualys API Best Practices: CyberSecurity Asset Management API

_The Qualys Security Blog’s _[API Best Practices Series]()_ is designed for Qualys customer programmers or stakeholders with a general knowledge of programming who want to implement best practices to ...

Continue Reading
CVE-2022-2664

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the compon ...

Continue Reading
Amazon Linux AMI : tomcat8 (ALAS-2022-1627)

The version of tomcat8 installed on the remote host is prior to 8.5.81-1.91. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS-2022-1627 advisory. - If a web applicati ...

Continue Reading
CVE-2022-21186

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.Read More ...

Continue Reading
CVE-2022-2598

Undefined Behavior for Input to API in GitHub repository vim/vim prior to 9.0.0100.Read More ...

Continue Reading

CVSS3 - MEDIUM

GitLab 12.5 < 15.0.5 / 15.1 < 15.1.4 / 15.2 < 15.2.1 Improper Authentication

According to its self-reported version, the instance of GitLab running on the remote web server is 12.5 prior to 15.0.5, 15.1 prior to 15.1.4, or 15.2 prior to 15.2.1. It is, therefore, affected by an ...

Continue Reading
Netwrix Auditor Web API Detection

Netwrix Auditor, an auditing and optimization solution used for compliance operations was detected on the remote host via the Netwrix Integrator API. Note: HTTP basic authentication credentials are ...

Continue Reading

Back to Main

Subscribe for the latest news: