c security update

**CentOS Errata and Security Advisory** CESA-2023:3741 The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API. Security Fix(es): * c-ares: 0-byte U ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Closing vulnerabilities in Decidim, a Ruby-based citizen participation platform

This blog post describes two security vulnerabilities in Decidim, a digital platform for citizen participation. Both vulnerabilities were addressed by the Decidim team with corresponding update releas ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-3670

In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to plac ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Preventing Web Application Access Control Abuse

### **SUMMARY** The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), U.S. Cybersecurity and Infrastructure Security Agency (CISA), and U.S. National Security Agency (NSA) ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 17, 2023 to July 23, 2023)

Last week, there were 62 vulnerabilities disclosed in 1035 WordPress Plugins and 90 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 36 Vulner ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

VMWare Aria Operations For Networks Remote Command Execution Exploit

VMWare Aria Operations for Networks (vRealize Network Insight) is vulnerable to command injection when accepting user input through the Apache Thrift RPC interface. This vulnerability allows a remote ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

VMWare Aria Operations For Networks Remote Command Execution Exploit

VMWare Aria Operations for Networks (vRealize Network Insight) is vulnerable to command injection when accepting user input through the Apache Thrift RPC interface. This vulnerability allows a remote ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2023-3956

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in vers ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: