pgadmin4 vulnerable to Code Injection

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the ...

Continue Reading

CVSS3 - HIGH

pgadmin4 vulnerable to Code Injection

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the ...

Continue Reading

CVSS3 - HIGH

CVE-2022-41040 and CVE-2022-41082 – zero-days in MS Exchange

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/12/19160500/abstract_black_matrix-990x400.jpg) ## Summary At the end of September, GTSC reported an attack on critical infras ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-41040 and CVE-2022-41082 – zero-days in MS Exchange

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/12/19160500/abstract_black_matrix-990x400.jpg) ## Summary At the end of September, GTSC reported an attack on critical infras ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Metasploit Weekly Wrap-Up

## A sack full of cheer from the Hacking Elves of Metasploit ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2022/12/metasploit-ascii-1-2.png) It is clear that the Metasploit elves ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Security Bulletin: IBM Cognos Analytics has addressed multiple vulnerabilities (CVE-2021-29469, CVE-2022-39160, CVE-2022-38708, CVE-2022-42003, CVE-2022-42004, CVE-2022-43883, CVE-2022-43887, CVE-2022-25647, CVE-2022-36364)

## Summary Security vulnerabilities have been addressed in IBM Cognos Analytics 11.2.4. These vulnerabilities have also been previously addressed in IBM Cognos Analytics 11.1.7 FP6 where applicable. T ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: IBM DataPower Gateway vulnerable to HTTP request smuggling (CVE-2022-35256)

## Summary This issue may affect the management interface for the API Connect Gateway Service. IBM has addressed the CVE. ## Vulnerability Details ** CVEID: **[CVE-2022-35256]() ** DESCRIPTION: **Node ...

Continue Reading

CVSS3 - CRITICAL

CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks

[![Veeam Backup and Replication](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() The U.S. Cybersecurity and Infrastructure Securi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: