Category: CVSS2 - HIGH
CVE-2023-2079

The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, a ...

Continue Reading
CVE-2023-2078

The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name ...

Continue Reading
CVE-2023-37286

SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary cod ...

Continue Reading
Exploit for SQL Injection in Progress Moveit Cloud

# CVE-2023-34362 POC for CVE-2023-34362 affecting MOVEit Transfe...Read More ...

Continue Reading
fusiondirectory – security update

A potential Cross Site Scripting (XSS) vulnerablity ([CVE-2022-36180](https://security-tracker.debian.org/tracker/CVE-2022-36180)) and session handling vulnerability ([CVE-2022-36179](https://security ...

Continue Reading
Secrets, Secrets Are No Fun. Secrets, Secrets (Stored in Plain Text Files) Hurt Someone

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Secrets are meant to be hidden or, at the very least, only known to a specif ...

Continue Reading
Silentbob Campaign: Cloud-Native Environments Under Attack

[![Silentbob Campaign](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Cybersecurity researchers have unearthed an attack infrast ...

Continue Reading
Patch me if you can: Cyberattack Series

Many organizations utilize third-party apps for identity security solutions to automate and unburden overtaxed IT admins from tedious tasks that employees can perform via self-service without IT assis ...

Continue Reading
Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to Envoy security bypass ( CVE-2023-27488)

## Summary Potential Enyoy security bypass vulnerability ( CVE-2022-25881) has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Refer to details for additional informat ...

Continue Reading
Quest NetVault Backup Server < 11.4.5 – Process Manager Service SQL Injection / Remote Code Execution

Post ContentRead More ...

Continue Reading
Load more