CVE-2025-25953

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to ...

Continue Reading
CVE-2025-25953

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to ...

Continue Reading
CVE-2025-25953

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to ...

Continue Reading
GHSA-MQ23-VVG7-XFM4 Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login

Impact A vulnerability in Rancher has been discovered, leading to a local user impersonation through SAML Authentication on first login. The issue occurs when a SAML authentication provider (AP) is co ...

Continue Reading
Security Bulletin: IBM Watson Speech Services Cartridge is vulnerable to a sensitive information exposure in golang-jwt [CVE-2024-51744]

Summary IBM Watson Speech Services Cartridge is vulnerable to a sensitive information exposure in golang-jwt, caused by improper error handling in ParseWithClaims [CVE-2024-51744]. Golang-jwt is used ...

Continue Reading
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login

Impact A vulnerability in Rancher has been discovered, leading to a local user impersonation through SAML Authentication on first login. The issue occurs when a SAML authentication provider (AP) is co ...

Continue Reading
CVE-2023-25574

jupyterhub-ltiauthenticator is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator 1.3.0 wasn't validating ...

Continue Reading
Security Bulletin: Multiple Vulnerabilities in IBM Event Streams

Summary Multiple vulnerabilities were addressed in IBM Event Streams version 11.6.1. Vulnerability Details CVEID:CVE-2024-47764 DESCRIPTION: jshttp cookie could allow a remote attacker to bypass secur ...

Continue Reading

Back to Main

Subscribe for the latest news: