CVE-2022-39042

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-43438

The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access rest ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: Multiple vulnerabilities affect IBM Tivoli Monitoring embedded WebSphere Application and IHS server

## Summary The following security issues have been identified in the WebSphere Application Server and IHS server included as part of IBM Tivoli Monitoring (ITM) portal server. ## Vulnerability Details ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

2022 Annual Metasploit Wrap-Up

![2022 Annual Metasploit Wrap-Up](https://blog.rapid7.com/content/images/2022/12/metasploit-haxmas-candy-canes.jpeg) It's been another gangbusters year for Metasploit, and the holidays are a time to g ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

OpenTSDB 2.4.0 Command Injection Exploit

This Metasploit module exploits an unauthenticated command injection vulnerability in the yrange parameter in OpenTSDB through 2.4.0 (CVE-2020-35476) in order to achieve unauthenticated remote code ex ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Exploit for Use After Free in Foxit Pdf Reader

# CVE-2022-40129 A use-after-free vulnerability exists in the J...Read More ...

Continue Reading

CVSS3 - HIGH

Exploit for Command Injection in Cisco Firepower Management Center

# CVE-2022-20925 A vulnerability in the web management interfac...Read More ...

Continue Reading

CVSS3 - HIGH

Exploit for Command Injection in Cisco Firepower Management Center

# CVE-2022-20926 A vulnerability in the web management interfac...Read More ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: