Tag: WebSecurity

  • Vulnerability Watch No71

    SPIP Flaw Enables Remote Code Execution at Critical Severity • SPIP Authorization Bypass Allows Administrator Account Takeover • SPIP Sitemap SQL Injection Exposes Database Secrets • Laci Synchroni OAuth Bug Enables User Impersonation • MoguBlog Authorization Flaw Allows Comment Deletion…

  • Topics Everyone Is Talking About No421

    Shopify Returns to Native Mobile Development After React Native Journey • Rust Becomes a Tier-1 Language at Microsoft • Save Your Cable Box: A Tribute to Forgotten Tech Gear • Streaming Subscriptions Now Cost 702 More Per Year Than in 2021 • Phishing Is Not the Users Fault Nor a DNS Problem…

  • Vulnerability Watch No68

    Critical cjose JWE Flaw Exposes Encrypted Data • cjose AES Key Wrap Bug Enables Heap Corruption • Maravel JWT Cache Issue Allows Token Replay • OPNsense NTP Module Bug Allows Root File Writes • n8n Expression Engine Flaw Risks Code Execution…

  • Vulnerability Watch No64

    FreeIPMI Critical Buffer Overflow Exposes FRU Handling • FreeIPMI Dell OEM Command Buffer Overflow Found • FreeIPMI Dell CMC Info Parser Hit by Critical Flaw • FreeIPMI iDRAC Parser Vulnerability Rated Critical • FreeIPMI Fujitsu Response Parsing Issue Discovered…

  • Vulnerability Watch No59

    Joomla Fabrik List Controller Allows Unauthorized Data Deletion • Joomla Fabrik Reveals Database Structure to Unauthenticated Users • Joomla Fabrik Allows Unauthenticated Directory Listing • Joomla Fabrik Permits Unauthenticated File Uploads • WordPress WS Form Plugin Exposes Critical PHP Object Injection Flaw…

  • Vulnerability Watch No58

    LeafWiki Account Update Bug Enables Role Escalation • RaTeX Parser Crash Creates Denial of Service Risk • WordPress Plugin Flaw Enables Privilege Escalation • WeeChat Authentication Timing Bug Exposes Hashes • LeafWiki File Traversal Bug Can Expose Local Data…

  • Vulnerability Watch No57

    Monkeytype Rate Limit Bypass Enables Abuse • Plate DOCX Conversion Flaw Exposes Internal Services • Link Preview JS DNS Rebinding Bypasses SSRF Protection • dbx Authentication Bypass Enables Database Takeover • NanaZip Archive Parsing Bug Risks Data Exposure…

  • Vulnerability Watch No53

    Kubernetes managed-serviceaccount flaw exposes cluster secrets • OpenSearch Dashboards request flaw enables remote denial of service • Dell PowerStore SDNAS NFS flaw can enable command execution • RabbitMQ Java client nesting bug triggers pre-authentication crashes • RabbitMQ Java client flaw enables massive pre-auth memory allocation…

  • Vulnerability Watch No51

    Zephyr Flash Syscall Flaw Enables Kernel Privilege Escalation • Glances Action Templates Can Reconstruct Shell Operators • Malformed Host Header Can Crash WebSocket Servers • Endpoint Privilege Management Tamper Protection Can Be Bypassed • PyCharm Jupyter MCP Tools Expose Unauthenticated Code Execution…

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…