Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.Read More ...
Continue ReadingJuly 19, 2022
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.Read More ...
Continue ReadingJuly 19, 2022
The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low ...
Continue ReadingJuly 19, 2022
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC ...
Continue ReadingJuly 19, 2022
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.Read More ...
Continue ReadingJuly 19, 2022
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.Read More ...
Continue ReadingJuly 19, 2022
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function.Read More ...
Continue ReadingJuly 19, 2022
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API clientRead More ...
Continue ReadingJuly 19, 2022
Back to Main