CVE-2023-0296

The Birthday attack against 64-bit block ciphers (CVE-2016-2183) was reported for the health checks port (9979) on the etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the et ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: Vulnerabilities in FasterXML affects IBM Common Licensing’s Administration And Reporting Tool (ART) and its Agent (217968, CVE-2020-36518)

## Summary Security Vulnerablities have been addressed in IBM Common Licensing. Faster-XML Jackson is a JSON to Java object conversion API (217968, CVE-2020-36518). A fix is available to address the v ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Improper Authentication

github.com/usememos/memos is vulnerable to improper authentication. The vulnerability allows a remote attacker to use the `Reset` API on any user without consent via IDOR.Read More ...

Continue Reading

CVSS3 - CRITICAL

Security Bulletin: B2B API of IBM Sterling B2B Integrator vulnerable to multiple issues due to CKEditor

## Summary IBM Sterling B2B Integrator has addressed the CKEditor security vulnerabilities in B2B API. ## Vulnerability Details ** CVEID: **[CVE-2021-32808]() ** DESCRIPTION: **CKEditor is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2022-39041

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify an ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-39042

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-43438

The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access rest ...

Continue Reading

CVSS3 - HIGH

CVE-2022-40740

Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execu ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: