Category: CVSS2 - HIGH
CVE-2023-3047

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.Read More ...

Continue Reading
CVE-2023-3049

Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection.This issue affects Lockcell: before 15.Read More ...

Continue Reading
CVE-2023-3050

Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15. ...

Continue Reading
Medium: xmlrpc

**Issue Overview:** XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forge ...

Continue Reading
tgstation-server cached user logins in legacy server

Please note this advisory is for a historical preexisting issue in the legacy server from 2018. It has long since been triaged. It is being moved here for visibility. The text below is copied from the ...

Continue Reading
Asylum Ambuscade: A Cybercrime Group with Espionage Ambitions

[![Cybercrime Group](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() The threat actor known as **Asylum Ambuscade** has been obse ...

Continue Reading
Important: xmlrpc

**Issue Overview:** An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server c ...

Continue Reading
(RHSA-2023:3409) Important: OpenShift Container Platform 4.12.20 packages and security update

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages ...

Continue Reading
Metasploit Weekly Wrap-Up

## Cloud Fun With EC2 ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2023/06/metasploit-sky-1-1-1.png) New ground was broken today with the addition of two PRs from community cont ...

Continue Reading
Metasploit Weekly Wrap-Up

## Cloud Fun With EC2 ![Metasploit Weekly Wrap-Up](https://blog.rapid7.com/content/images/2023/06/metasploit-sky-1-1-1.png) New ground was broken today with the addition of two PRs from community cont ...

Continue Reading
Load more