An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.Read More ...
Continue ReadingAugust 29, 2023
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.Read More ...
Continue ReadingAugust 29, 2023
A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navi ...
Continue ReadingAugust 28, 2023
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitH ...
Continue ReadingAugust 28, 2023
SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.Read More ...
Continue ReadingAugust 28, 2023
Zoho ManageEngine ADManager Plus through 7186 is vulnerable to 2FA bypass.Read More ...
Continue ReadingAugust 28, 2023
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in ses ...
Continue ReadingAugust 28, 2023
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).Read More ...
Continue ReadingAugust 28, 2023
Back to Main