Tag: CredentialTheft

  • Vulnerability Watch No60

    AWX Archive Extraction Path Traversal • HCL Hive Third-Party Component Vulnerability • GIMP PCX Plugin Memory Corruption Bug • rConfig Authentication Bypass Creates Admin Accounts • NetworkManager WPA-Enterprise Validation Flaw…

  • Vulnerability Watch No37

    Discourse Rich Text Editor Flaw Enables Stored XSS • Multicluster Global Hub Flaw Lets Compromised Hubs Falsify Data • Malicious Git Config Can Trigger Code Execution in Goose Review • SPIP SQLite Installations Exposed to Authenticated Command Execution • Malicious use-context-selector Commits Compromised Developer Machines…

  • Vulnerability Watch No23

    Hashi Vault JS Flaw Enables Path and Query Injection • Defaults Deep Library Vulnerable to Prototype Pollution • DSSRF DNS Handling Bug Reopens SSRF Paths • Vault Webhook Flaw Can Leak Kubernetes Service Account Tokens • cPanel Database Rename Flaw Enables Root-Context SQL Execution…

  • Vulnerability Watch No20

    TinyWeb Path Traversal Exposes Sensitive Server Files • Malformed Requests Can Crash TinyWeb Servers • Ordinary Requests Can Exhaust TinyWeb Memory • Rouille Request Smuggling Can Bypass Access Controls • QTI Neon Relay Amplification Threatens Game Hosts…

  • Vulnerability Watch No15

    Pre-Auth Heap Overflow in libssh2 Clients • libssh2 Bounds Check Bug Leaks Memory • Stored XSS Hits Loytec OPC XML-DA • Loytec Privilege Management Flaw Enables Password Resets • Critical Symlink Attack Leads to Root on Loytec…