CVE-2023-3956

The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in vers ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Internet Bug Bounty: [CVE-2023-22799] Possible ReDoS based DoS vulnerability in GlobalID

I made a report and patch at https://hackerone.com/reports/1696752. https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerability-in-globalid/82127 > There is a possible D ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2023:4289) Important: OpenShift API for Data Protection (OADP) 1.0.11 security and bug fix update

OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both f ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

(RHSA-2023:4293) Moderate: Migration Toolkit for Containers (MTC) 1.7.11 security and bug fix update

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the M ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

Incorrect Permission Assignment

gitlab is vulnerable to Incorrect Permission Assignment. The vulnerability exists due to improper access control in the library, which allows an attacker to edit the approval rules via the API by an u ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Denial Of Service (DoS)

gitlab is vulnerable to Denial Of Service (DoS). The vulnerability exists due to the lack of length validation of the library, which allows an attacker to create large issue descriptions via GraphQL, ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: IBM Watson Discovery Cartridge for IBM Cloud Pak for Data affected by vulnerability in gRPC

## Summary IBM Watson Discovery Cartridge for IBM Cloud Pak for Data contains a vulnerable version of gRPC. ## Vulnerability Details ** CVEID: **[CVE-2023-32732]() ** DESCRIPTION: **gRPC is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Remote Code Execution (RCE)

gitlab is vulnerable to Remote Code Execution (RCE). The vulnerability exists due to the lack of input validation of the library, which allows an attacker to inject and execute malicious code via the ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: