Category: CVSS2 - MEDIUM
What are JWT Injections, and Why do You Need to Know About Them

JSON Web Tokens (JWTs for short) are the new standard for transmitting identity information in the digital age. JWTs are JSON objects that act as an identifier for your user or application. They’re u ...

Continue Reading
What are JWT Injections, and Why do You Need to Know About Them

JSON Web Tokens (JWTs for short) are the new standard for transmitting identity information in the digital age. JWTs are JSON objects that act as an identifier for your user or application. They’re u ...

Continue Reading
dotCMS Unrestricted Upload of File Vulnerability

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage l ...

Continue Reading
php:7.4 security update

php [7.4.19-4] - fix uninitialized array in pg_query_params() leading to RCE CVE-2022-31625Read More ...

Continue Reading
php:7.4 security update

php [7.4.19-4] - fix uninitialized array in pg_query_params() leading to RCE CVE-2022-31625Read More ...

Continue Reading
(RHSA-2022:6158) Moderate: php:7.4 security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625) For more details ...

Continue Reading
(RHSA-2022:6158) Moderate: php:7.4 security update

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625) For more details ...

Continue Reading
Microsoft Exchange Server ChainedSerializationBinder Remote Code Execution Exploit

This Metasploit module exploits vulnerabilities within the ChainedSerializationBinder as used in Exchange Server 2019 CU10, Exchange Server 2019 CU11, Exchange Server 2016 CU21, and Exchange Server 20 ...

Continue Reading
GO-2022-0947

In Mellium mellium.im/xmpp, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to ...

Continue Reading
Microsoft Exchange Server ChainedSerializationBinder Remote Code Execution

Post ContentRead More ...

Continue Reading
Load more