(0Day) D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this vulnerability. The s ...

Continue Reading
CVE-2024-33891

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the in ...

Continue Reading
MailCleaner SOAP Service dumpConfiguration os command injection

A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects the function getStats/Services_silentDump/Services_stopStartMTA/Config_saveDateT ...

Continue Reading
php: Fix of 2 CVEs

CVE-2022-31629: Add cookie integrity validation CVE-2024-2756: Move cookie integrity validation...Read More ...

Continue Reading
RHEL 6 / 7 : rh-php70-php (RHSA-2019:3724)

The remote Redhat Enterprise Linux 6 / 7 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2019:3724 advisory. php: underflow in env_path_info in fpm_main.c ( ...

Continue Reading
Debian dla-3810 : libapache2-mod-php7.3 – security update

The remote Debian 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3810 advisory. In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerabi ...

Continue Reading
[SECURITY] [DLA 3810-1] php7.3 security update

Debian LTS Advisory DLA-3810-1 [email protected] https://www.debian.org/lts/security/ Guilhem Moulin May 07, 2024 https: ...

Continue Reading
Debian: Security Advisory (DLA-3810-1)

The remote host is missing an update for the...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: