CVE-2023-22374: F5 BIG-IP Format String Vulnerability

![CVE-2023-22374: F5 BIG-IP Format String Vulnerability](https://blog.rapid7.com/content/images/2023/02/GettyImages-1352385622.jpg) While following up our [previous work on F5's BIG-IP devices](), Rap ...

Continue Reading

CVSS3 - HIGH

RHEL 8 : Red Hat JBoss Enterprise Application Platform 7.4.9 Security update (Important) (RHSA-2023:0553)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0553 advisory. - jquery: Cross-site scripting via cross- ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Additional Supply Chain Vulnerabilities Uncovered in AMI MegaRAC BMC Software

[![BMC Supply Chain Vulnerabilities](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Two more supply chain security flaws have be ...

Continue Reading

CVSS3 - CRITICAL

RHEL 9 : Red Hat JBoss Enterprise Application Platform 7.4.9 Security update (Important) (RHSA-2023:0554)

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0554 advisory. - jquery: Cross-site scripting via cross- ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

RHEL 7 : Red Hat JBoss Enterprise Application Platform 7.4.9 Security update (Important) (RHSA-2023:0552)

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0552 advisory. - jquery: Cross-site scripting via cross- ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

(RHSA-2023:0554) Important: Red Hat JBoss Enterprise Application Platform 7.4.9 Security update

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.9 serves ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

CVE-2023-22900

Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete databas ...

Continue Reading

CVSS3 - CRITICAL

CVE-2022-39060

ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER s ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: