-
Vulnerability Watch No46
Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…
-
Vulnerability Watch No38
Critical SQL Injection Hits Travel Agency Management System • ASUS Utility Flaw Can Enable Local Privilege Escalation • Hard-Coded Key Puts SAP BusinessObjects Credentials at Risk • SAP ABAP Authorization Flaw Exposes Database Operations • SAP Approuter Token Validation Flaw Can Leak Credentials…
-
Vulnerability Watch No10
Critical Unauthenticated RCE in Autel Maxi Charger • WordPress WP Foodbakery File Deletion Flaw Can Lead to RCE • Veeam Software Appliance Privilege Escalation to Root • Netty OCSP Validation Bug Enables Revocation Check Bypass • Netty HTTP2 Memory Leak Can Crash JVM…