CVE-2022-25168

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemory ...

Continue Reading
WordPress Social Slider Feed plugin <= 2.0.5 – Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via API Key discovered by WPScan in WordPress Social Slider Feed plugin (versions Read More ...

Continue Reading
WordPress Sensei LMS plugin <= 4.4.3 – Unauthenticated Private Messages Disclosure via Rest API vulnerability

Unauthenticated Private Messages Disclosure via Rest API vulnerability discovered by Veshraj Ghimire in WordPress Sensei LMS plugin (versions Read More ...

Continue Reading
Attackers leveraging Dark Utilities “C2aaS” platform in malware campaigns

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYnN_Ui_mtMyFummOqncAQ1V0H_Wt6jnBQVrimBv65KHMrPKcEjtaBTo3XPEmclNwoOpmfAq1irrO4FMoDQu_8LE2mysSShtSQ6p4toIckN-NiCBVM1OegoBTjbL8VZ9D0rKy1kL ...

Continue Reading
Research Shows the Annual Cost of API Security-related Breaches is Mind-blowing

[Application Programming Interfaces]() (APIs) have emerged as useful tools that streamline business operations and enhance the digital experience for customers. As their use has become more widespread ...

Continue Reading
A Wide Reduction Trick

In line with the original spirit of Cryptography Dispatches, this is a quick[1] issue to talk about a neat bit of cryptography engineering I encountered. ## The structure of an ECC implementation Elli ...

Continue Reading
CVE-2022-2598

Undefined Behavior for Input to API in GitHub repository vim/vim prior to 9.0.0100.Read More ...

Continue Reading
CVE-2022-32964

OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service.Read ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: