‼ CVE-2021-4252 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76. It is recommended to apply a patch to fix this issue. The identifier VDB-216209 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
🕴 GitHub Expands Secret Scanning, 2FA Across Platform 🕴
📖 Read
via "Dark Reading".
Microsoft-owned GitHub is taking steps to secure the open source software ecosystem by rolling out security features to protect code repositories.📖 Read
via "Dark Reading".
Dark Reading
GitHub Expands Secret Scanning, 2FA Across Platform
Microsoft-owned GitHub is taking steps to secure the open source software ecosystem by rolling out security features to protect code repositories.
🗓️ Safeurl HTTP library brings SSRF protection to Go applications 🗓️
📖 Read
via "The Daily Swig".
Prizes offered to anyone who can bypass the library and capture the flag📖 Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Safeurl HTTP library brings SSRF protection to Go applications
Prizes offered to anyone who can bypass the library and capture the flag
‼ CVE-2022-47500 ‼
📖 Read
via "National Vulnerability Database".
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding. User please upgrade to 1.1.0 to fix this issue.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-44755 ‼
📖 Read
via "National Vulnerability Database".
IBM Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44754 ‼
📖 Read
via "National Vulnerability Database".
IBM Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-3876 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-216245 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-3875 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216244.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37392 ‼
📖 Read
via "National Vulnerability Database".
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44753 ‼
📖 Read
via "National Vulnerability Database".
IBM Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44751 ‼
📖 Read
via "National Vulnerability Database".
IBM Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-3877 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected is an unknown function of the component URL Field Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. VDB-216246 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-42453 ‼
📖 Read
via "National Vulnerability Database".
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in user, with insufficient warnings when attempting to run the script.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40743 ‼
📖 Read
via "National Vulnerability Database".
Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1.4 or later versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44750 ‼
📖 Read
via "National Vulnerability Database".
IBM Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44754.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44752 ‼
📖 Read
via "National Vulnerability Database".
IBM Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-38653 ‼
📖 Read
via "National Vulnerability Database".
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-32749 ‼
📖 Read
via "National Vulnerability Database".
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4024 ‼
📖 Read
via "National Vulnerability Database".
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)📖 Read
via "National Vulnerability Database".
‼ CVE-2021-4259 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in phpRedisAdmin up to 1.17.3. It has been classified as problematic. This affects the function authHttpDigest of the file includes/login.inc.php. The manipulation of the argument response leads to use of wrong operator in string comparison. The name of the patch is 31aa7661e6db6f4dffbf9a635817832a0a11c7d9. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216267.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-4261 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.6 is able to address this issue. The name of the patch is 29522c90ca1cebfce6453a5af5a45281d99b0646. It is recommended to upgrade the affected component. VDB-216270 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".