Category: CVSS3 - CRITICAL
(RHSA-2023:0777) Critical: OpenShift Container Platform 4.9.56 security update

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages ...

Continue Reading
php:8.0 security update

php [8.0.27-1] - rebase to 8.0.27Read More ...

Continue Reading
Q4-2022 API ThreatStats™ Report

We’re pleased to present the latest quarterly review and analysis of API vulnerabilities and exploits. This time, we’re going to split our discussion into two parts: today this quarterly rev ...

Continue Reading
Q4-2022 API ThreatStats™ Report

We’re pleased to present the latest quarterly review and analysis of API vulnerabilities and exploits. This time, we’re going to split our discussion into two parts: today this quarterly rev ...

Continue Reading
Rocky Linux 8 : php:8.0 (RLSA-2023:0848)

The remote Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2023:0848 advisory. Note that Nessus has not tested for these issues but ha ...

Continue Reading
What’s Next After Log4Shell?

## _How to deal with the next open-source vulnerability using custom scripts_ A critical vulnerability in Apache’s Log4j Java-based logging utility (CVE-2021-44228) was previously referred to as ...

Continue Reading
Debian DLA-3325-1 : openssl – LTS security update

The remote Debian 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-3325 advisory. - AES OCB mode for 32-bit x86 platforms using the AES-NI assemb ...

Continue Reading
Security Updates for Microsoft Office Online Server (February 2023)

The Microsoft Office Web Apps installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability: - A remote code execution vulnerability. An una ...

Continue Reading
Apache SOAP contains unauthenticated RPCRouterServlet

** UNSUPPORTED WHEN ASSIGNED ** In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the cl ...

Continue Reading
CVE-2022-3843

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a lim ...

Continue Reading
Load more