CVE-2022-45137

The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality an ...

Continue Reading

CVSS3 - MEDIUM

CVE-2022-45140

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromi ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-45139

A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead ...

Continue Reading

CVSS3 - MEDIUM

CVE-2022-45138

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated ...

Continue Reading

CVSS3 - CRITICAL

Important Photon OS Security Update – PHSA-2023-3.0-0538

Updates of ['telegraf', 'linux-secure', 'harfbuzz', 'kafka', 'bindutils', 'openssl', 'linux-rt', 'python3', 'gnutls', 'containerd', 'linux', 'linux-esx', 'linux-aws'] packages of Photon OS have been r ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

SUSE SLED15 / SLES15 / openSUSE 15 Security Update : php7 (SUSE-SU-2023:0513-1)

The remote SUSE Linux SLED15 / SLES15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0513-1 advisory. - Password_verify() a ...

Continue Reading

CVSS3 - CRITICAL

SUSE SLES15 / openSUSE 15 Security Update : php7 (SUSE-SU-2023:0514-1)

The remote SUSE Linux SLES15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0514-1 advisory. - Password_verify() always ret ...

Continue Reading

CVSS3 - CRITICAL

SUSE SLES12 Security Update : php74 (SUSE-SU-2023:0515-1)

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:0515-1 advisory. - Password_verify() always return true with ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: