An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.Read M ...
Continue ReadingJune 21, 2022
IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.Read More ...
Continue ReadingJune 21, 2022
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.Read More ...
Continue ReadingJune 21, 2022
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and ...
Continue ReadingJune 21, 2022
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).Read More ...
Continue ReadingJune 21, 2022
An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.Read More ...
Continue ReadingJune 21, 2022
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from ...
Continue ReadingJune 21, 2022
AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows c ...
Continue ReadingJune 21, 2022
Back to Main