[SECURITY] Fedora 38 Update: nmstate-2.2.10-4.fc38

Nmstate is a library with an accompanying command line tool that manages ho st networking settings in a declarative manner and aimed to satisfy enterprise needs to manage host networking through a nor ...

Continue Reading

CVSS3 - HIGH

Improper Privilege Management

microweber/microweber is vulnerable to Improper Privilege Management . The vulnerability exists due lack of authorization checks in the `apiResource` parameter of `api.php` which allows an attacker to ...

Continue Reading

CVSS3 - HIGH

EulerOS Virtualization 3.0.2.0 : libvirt (EulerOS-SA-2023-1687)

According to the versions of the libvirt packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities : - A use-after-free flaw was fou ...

Continue Reading

CVSS3 - MEDIUM

Improper Authorization

modoboa is vulnerable to Improper Authorization. The vulnerability exists due to missing authorization checks on the `/api/v2/parameters/core/` API endpoint which allows an attacker to gain sensitive ...

Continue Reading

CVSS3 - CRITICAL

Command injection in OpenTSDB

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Cross Site Scripting in OpenTSDB

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the bro ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Amazon Linux AMI : tomcat7 (ALAS-2023-1738)

The version of tomcat7 installed on the remote host is prior to 7.0.109-1.42. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS-2023-1738 advisory. - Apache Commons Fi ...

Continue Reading

CVSS3 - HIGH

CVE-2017-20184

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any ...

Continue Reading

CVSS3 - HIGH

Back to Main

Subscribe for the latest news: