Quest NetVault Backup NVBUJobCountHistory SQL Injection (CVE-2017-17420)

An SQL injection vulnerability exists in the Server Process Manager Service of Quest NetVault Backup. The vulnerability is due to improper validation of user-supplied input on JSON-RPC requests invoki ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: For IBM Cloudpak for Watson AIOPS 3.5.1

## Summary This SB contains a list for all CVE's listed here - CVE-2022-36083, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166, CVE-2022-21797, CVE-2022-35941, CVE-2021-42248, CVE-2021-42836, CVE-2022- ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

8 KB is not enough: why WAFs can’t protect APIs

WAFs were a top-notch security instrument a decade ago, but now they are not. They fail to protect APIs. Meanwhile, the number of API-specific vulnerabilities grew more than twofold in 2022. According ...

Continue Reading
Reddit: Unrestricted File Upload on reddit.secure.force.com

## Summary: Reddit.secure.force.com is Reddit SalesForce instance. Attacker is able to send attachments of disallowed filetypes to this server. The attacker is able to send malicious documents such as ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Monero: monerod JSON RPC server remote DoS

Monero daemon (monerod) does not limit Content-length variable when processing incoming HTTP requests. We can force monerod to allocate arbitrary amount of memory. How to reproduce: 1) compile monero ...

Continue Reading
Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks

Microsoft has observed the Sliver command-and-control (C2) framework now being adopted and integrated in intrusion campaigns by [nation-state threat actors](), cybercrime groups directly supporting [r ...

Continue Reading
Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks

Microsoft has observed the Sliver command-and-control (C2) framework now being adopted and integrated in intrusion campaigns by [nation-state threat actors](), cybercrime groups directly supporting [r ...

Continue Reading
Security update for trivy (moderate)

An update that fixes three vulnerabilities is now available. Description: This update for trivy fixes the following issues: Update to version 0.30.4: * fix: remove the first arg when running ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: