CVE-2022-1941 - Protocol Buffers Parsing Vulnerability Can Lead To Out-Of-Memory Denial of Service
Imagine your service starts crashing because of a single malicious message. That’s exactly what CVE-2022-1941 is about—a parsing bug in Google&
CVE-2022-36390 Totalsoft Event Calendar - Calendar plugin = 1.4.6 has an authenticated XSS vulnerability.
An attacker can host a maliciously crafted website and trick a user into clicking a malicious link, which will execute arbitrary PHP code on the
CVE-2022-23952 Keylime's old keylime.conf file contained sensitive data as it was readable by the world.
This data is now safely stored in your server’s configuration file. This change was made to reduce the risk of installing keylime on a
CVE-2022-39220 SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are vulnerable to Cross-site scripting (XSS) attacks due to a WebClient bug. An update is available.
SFTPGo is susceptible to Cross-site scripting (XSS) vulnerabilities in the WebClient component. According to the vendor, these vulnerabilities have been fixed in version 2.
CVE-2022-38550 An XSS vulnerability in Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML.
This XSS flaw arises from the fact that the /weibo/list component does not properly sanitize user-supplied input before executing it. An attacker can
Episode
00:00:00
00:00:00