Category: CVSS3 - CRITICAL
Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to Envoy security bypass ( CVE-2023-27488)

## Summary Potential Enyoy security bypass vulnerability ( CVE-2022-25881) has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Refer to details for additional informat ...

Continue Reading
Quest NetVault Backup Server < 11.4.5 – Process Manager Service SQL Injection / Remote Code Execution

Post ContentRead More ...

Continue Reading
GitHub: Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User’s Projects in Project V2 GraphQL api

An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app i ...

Continue Reading
Improper Control of Generation of Code (‘Code Injection’)

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.Read More ...

Continue Reading
Cobbler before 3.3.0 allows log poisoning

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.Read More ...

Continue Reading
Cobbler Remote Code Execution Vulnerability

Cobbler is a network installation server suite that is primarily used to quickly build Linux network installation environments. remote code execution vulnerability exists in versions of Cobbler prior ...

Continue Reading
Exploit for OS Command Injection in Sixapart Movable Type

# CVE-2021-20837 XMLRPC - RC...Read More ...

Continue Reading
(RHSA-2021:4702) Moderate: Satellite 6.10 Release

Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized too ...

Continue Reading
PHP vulnerabilities

## Releases * Ubuntu 16.04 ESM ## Packages * php7.0 - HTML-embedded scripting language interpreter It was discovered that PHP incorrectly handled certain scripts. An attacker could possibly use th ...

Continue Reading
CVE-2022-35405

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with ...

Continue Reading
Load more