CVE-2022-32994 An arbitrary file upload vulnerability was found in Halo CMS v1.5.3.
An attacker could leverage this vulnerability to execute code on the affected system or obtain sensitive information. The security risk of malicious file uploads is
CVE-2022-31090 - Sensitive Authorization Header Leak in Guzzle When Following Redirects—What You Should Know
If you use Guzzle, the popular PHP HTTP client, for making web requests, there's an important security vulnerability you need to know about—
CVE-2022-31626 With pdo_mysql extension and mysqlnd driver, if the third party allows to connect to the host, and the password is of excessive length, it can't be decrypted by the server.
It has been reported that the vulnerability exists in pdo_mysql extension with mysqlnd driver, which is currently being patched by most of the vendors.
CVE-2022-31625 Postgres database extension doesn't like invalid parameters in older versions of PHP. This can lead to memory being freed using uninitialized data as pointers.
Parameter sniffing is a security feature in most modern programming languages that prevents accidental access to uninitialized data by checking the type of each variable
CVE-2022-1657 - Critical Path Traversal and Local File Inclusion in Jupiter and JupiterX WordPress Themes
The CVE-2022-1657 vulnerability exposes millions of WordPress sites running vulnerable versions of the popular Jupiter (<= 6.10.1) and JupiterX (<= 2.
Episode
00:00:00
00:00:00