Category: CVSS2 - MEDIUM
Authorization Bypass

gitlab is vulnerable to Authorization Bypasses. This vulnerability occurs due to a flaw in the way that GitLab handles OAuth subscriptions. An attacker can exploit this vulnerability to generate OAuth ...

Continue Reading
Python Parsing Error Enabling Bypass CVE-2023-24329

### Overview urllib.parse is a very basic and widely used basic URL parsing function in various applications. ### Description An issue in the urllib.parse component of Python before v3.11 allows attac ...

Continue Reading
Improper Authorization

gitlab is vulnerable to Improper Authorization. The vulnerability exists due to improper access to some particular fields through the GraphQL API which allows an attacker to perform unauthorized actio ...

Continue Reading
Request-Baskets 1.2.1 Server-Side Request Forgery

Post ContentRead More ...

Continue Reading
Moderate Photon OS Security Update – PHSA-2023-5.0-0068

Updates of ['grpc'] packages of Photon OS have been released.Read More ...

Continue Reading
CVE-2023-4283

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization ...

Continue Reading
CVE-2023-4282

The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and i ...

Continue Reading
Request-Baskets v1.2.1 – Server-side request forgery (SSRF)

Post ContentRead More ...

Continue Reading
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 31, 2023 to August 6, 2023)

Last week, there were 29 vulnerabilities disclosed in 24 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 18 Vulnerab ...

Continue Reading
CVE-2023-4277

The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' functi ...

Continue Reading
Load more