Privilege Escalation

dolibarr/dolibarr is vulnerable to privilege escalation. The vulnerability exists due to improper authorization checks in the library, allowing an attacker to escalate privileges via crafted API call, ...

Continue Reading

CVSS3 - CRITICAL

Apache SOAP contains unauthenticated RPCRouterServlet

** UNSUPPORTED WHEN ASSIGNED ** In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the cl ...

Continue Reading

CVSS3 - CRITICAL

Concrete CMS vulnerable to Cross-site Request Forgery

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.Read More ...

Continue Reading

CVSS3 - HIGH

Security Bulletin: Rational Asset Analyzer is vulnerable to denial of service due to GraphQL Java (CVE-2022-37734)

## Summary There is a vulnerability in IBM WebSphere Application Server Liberty used by Rational Asset Analyzer. This vulnerability is located in the GraphQL Java library used by IBM WebSphere Applica ...

Continue Reading

CVSS3 - HIGH

Gitea Git Fetch Remote Code Execution Exploit

This Metasploit module exploits the Git fetch command in the Gitea repository migration process to allow for remote command execution on the system. This vulnerability affect Gitea versions prior to 1 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Gitea Git Fetch Remote Code Execution

Post ContentRead More ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

AlmaLinux 9 : php (ALSA-2022:5904)

The remote AlmaLinux 9 host has packages installed that are affected by a vulnerability as referenced in the ALSA-2022:5904 advisory. Note that Nessus has not tested for this issue but has instead rel ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Deserialization Of Untrusted Data

soap is vulnerable to untrusted data deserialization. The vulnerability exists due to lack of authentication in `RPCRouterServlet` which allows an attacker to execute arbitrary code in to the system.R ...

Continue Reading

CVSS3 - CRITICAL

Back to Main

Subscribe for the latest news: