Microsoft Edge (Chromium) < 103.0.1264.71 Multiple Vulnerabilities

The version of Microsoft Edge installed on the remote Windows host is prior to 103.0.1264.71. It is, therefore, affected by multiple vulnerabilities as referenced in the July 22, 2022 advisory. - : ...

Continue Reading
CVE-2018-25045

Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.Read More ...

Continue Reading
Debian DSA-5186-1 : djangorestframework – security update

The remote Debian 10 host has packages installed that are affected by a vulnerability as referenced in the dsa-5186 advisory. - A flaw was found in Django REST Framework versions before 3.12.0 and b ...

Continue Reading
CVE-2022-34112

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.Read More ...

Continue Reading
CVE-2022-34113

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.Read More ...

Continue Reading
Security update for python-M2Crypto (important)

An update that fixes one vulnerability is now available. Description: This update for python-M2Crypto fixes the following issues: - CVE-2020-25657: Fixed Bleichenbacher timing attacks in the RSA ...

Continue Reading
Cloud Threat Detection: To Agent or Not to Agent?

![Cloud Threat Detection: To Agent or Not to Agent?](https://blog.rapid7.com/content/images/2022/07/blog-hero-bg--1-.jpg) The shift towards cloud and [cloud-native application architectures]() represe ...

Continue Reading
CVE-2022-31168

Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administra ...

Continue Reading

Back to Main

Subscribe for the latest news: