Vulnerability News
4.78K subscribers
2 photos
42K links
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace!

Group: @VulnerabilityNewsGroup
Download Telegram
Microsoft Identity Bounty Program Pays $500 to $100,000 for Bugs
Read More
[papers] VLAN Hopping Attack
Read More
[papers] Abusing Kerberos - Kerberoasting
Read More
[remote] HomeMatic Zentrale CCU2 - Remote Code Execution
Read More
[webapps] Open-AudIT Community 2.1.1 - Cross-Site Scripting
Read More
[webapps] FTP2FTP 1.0 - Arbitrary File Download
Read More
[webapps] Modx Revolution < 2.6.4 - Remote Code Execution
Read More
#0daytoday #FTP2FTP 1.0 - Arbitrary File Download Vulnerability [webapps #exploits #Vulnerability #0day #Exploit]
Read More
#0daytoday #LinuxKernel 4.14.8 Sign Extension Local Privilege Escalation Exploit [#0day #Exploit]
Read More
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Published at: July 16, 2018 at 03:29PM
View on website
The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml.
Published at: July 18, 2018 at 04:29PM
View on website
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
Published at: July 16, 2018 at 10:29PM
View on website
Venmo users: time to hide your drug deals and excessive pizza consumption
Read More
Automated money-laundering scheme found in free-to-play games
Read More
Trends in malware – ransomware, cryptojacking, what next? [PODCAST]
Read More
Privacy Advocates Say Kelsey Smith Act Gives Police Too Much Power
Read more
[webapps] WordPress Plugin All In One Favicon 4.6 - Cross-Site Scripting
Read More
Google hit with $5.1b fine in EU’s Android antitrust case
Read More
[webapps] MyBB New Threads Plugin 1.1 - Cross-Site Scripting
Read More
Critical Authentication Flaws in Cisco Policy Suite Patched
Read more
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
Published at: July 19, 2018 at 03:29PM
View on website