CVE-2022-30287 - Exploiting Arbitrary PHP Object Deserialization in Horde Groupware Webmail Edition
CVE-2022-30287 affects Horde Groupware Webmail Edition up to version 5.2.22. This vulnerability is pretty scary: it allows an attacker to inject
CVE-2022-1634 After free in the Browser UI of Google Chrome prior to 101.0.4951.64 allowed a remote attacker to exploit heap corruption.
CVE-2018-4878 was discovered by Gary Steele. After the heap corruption occurs, the attacker can force the browser to crash or execute arbitrary code
CVE-2022-31168 Zulip is an open source team chat tool. In Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants them administrator privileges.
Zulip teams are encouraged to update their Zulip servers to version 5.5 as soon as possible. An upgrade is simple and quick. Also, be
CVE-2022-2297 - Critical Unrestricted File Upload Vulnerability in SourceCodester Clinics Patient Management System 2.
TL;DR:
A very serious security vulnerability, CVE-2022-2297, was found in the SourceCodester Clinics Patient Management System 2.. Through a flaw in the
CVE-2022-31580 The sanojtharindu/caretakerr repository through 2021-05-17 uses the Flask send_file function unsafely.
This function will try to access any path that it is passed, and as a result, it is possible for an attacker to craft a
Episode
00:00:00
00:00:00