CVE-2022-2421 : SOCKET.IO JS LIBRARY ATTACHMENT PARSER SQL INJECTION
Description Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder
Description Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder
Description An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit
Description A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of
Description On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be
Description A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message
Description Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon
What is PCI DSS? The Payment Card industry data security (PCI DSS), was unfolded to encourage and enhance card holder
Description In Spring Security versions 5.5.6 and 5.6.3 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed
Description Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue
Description A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function ipaddr_link_get
Description A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.14 could
Description An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific
What is SSL? SSL stands for Secure Sockets Layer. It is a standard technology for establishing an encrypted link between
Description An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure.
Description Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX
Description A vulnerability was found in Fortinet FortiOS and FortiProxy. It has been classified as very critical. This affects an
What is Directory Traversal? Directory traversal is also known as file path traversal. It is a web security flaw that
Description Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads
What Is Credential Stuffing? A cyberattack known as “credential stuffing” occurs when a cybercriminal gains access to user accounts at
Description Generex CS141 before 2.08 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh
Description A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege
Description An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable
What is REST API? REST is the acronym of Representational State Transfer (REST). It is an architectural style or pattern
Description isolated-vm is a library for nodejs which gives the user access to v8’s Isolate interface. In versions 4.3.6 and