Tag: Authentication

  • Vulnerability Watch No73

    vLLM Loader Flaw Enables Remote Code Execution • AVideo Scheduler Bug Exposes Email Jobs • MemberPress Flaw Allows Administrator Account Takeover • YayPricing Plugin Enables Stored Script Attacks • Zonify Plugin Leaks Authentication Tokens…

  • Vulnerability Watch No72

    GitLab Duo Chat Flaw Exposes Sensitive Search Credentials • GitLab Repository API Bug Allows Unauthenticated File Reads • stb_vorbis Heap Overflow Can Corrupt Memory • OpenStack Keystone Delegated Tokens Expose Credentials • Default Admin Password Leaves Inventory Component Exposed…

  • Topics Everyone Is Talking About No421

    Shopify Returns to Native Mobile Development After React Native Journey • Rust Becomes a Tier-1 Language at Microsoft • Save Your Cable Box: A Tribute to Forgotten Tech Gear • Streaming Subscriptions Now Cost 702 More Per Year Than in 2021 • Phishing Is Not the Users Fault Nor a DNS Problem…

  • Vulnerability Watch No68

    Critical cjose JWE Flaw Exposes Encrypted Data • cjose AES Key Wrap Bug Enables Heap Corruption • Maravel JWT Cache Issue Allows Token Replay • OPNsense NTP Module Bug Allows Root File Writes • n8n Expression Engine Flaw Risks Code Execution…

  • Vulnerability Watch No66

    YouTrack REST API Authorization Gap Exposes Resources • YouTrack Link Controls Allow Unauthorized Entity Changes • YouTrack Whiteboard Clone Flaw Exposes Issue Links • YouTrack Token Cache Issue Enables Cross-Tenant Token Theft • YouTrack Group Management Bug Enables Privilege Escalation…

  • Vulnerability Watch No65

    undici Cache Bug Enables Cross-Origin Data Exposure • undici TLS Validation Bypass Hits BalancedPool • PowerJob Worker Unauthenticated RCE Exposes Servers • IBM ContextForge Session Leak Exposes Data • IBM ContextForge Bug Allows Credential Theft…

  • Framework Release Watch No16

    Laravel 13.30.0 expands queues, collections, and SQL Server support • Laravel 12.69.0 tightens cookie authentication

  • Vulnerability Watch No58

    LeafWiki Account Update Bug Enables Role Escalation • RaTeX Parser Crash Creates Denial of Service Risk • WordPress Plugin Flaw Enables Privilege Escalation • WeeChat Authentication Timing Bug Exposes Hashes • LeafWiki File Traversal Bug Can Expose Local Data…

  • Vulnerability Watch No56

    Splunk flaw lets lower-privileged users write arbitrary dispatch metadata • Splunk Monitoring Console link flaw enables unauthorized searches • Splunk authentication weakness can enable forged admin sessions • Splunk SPL2 API issue allows unauthorized module deletion • Splunk Web XML weakness enables operating system command execution…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…