|
You are here |
www.uptycs.com | ||
| | | | |
www.imperva.com
|
|
| | | | | Recently, a critical vulnerability in the widely used Apache OFBiz framework was disclosed, designated CVE-2024-45195. This vulnerability allows for unauthenticated remote code execution (RCE), making it an especially dangerous flaw for organizations using OFBiz in their business operations. An attacker without valid credentials can exploit missing view authorization checks in the web application, bypassing previous [...] | |
| | | | |
blog.talosintelligence.com
|
|
| | | | | Update History DateDescription of UpdatesDec. 20, 2021 Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts. Dec. 18, 2021 Additional mitigation guidance; updated coverage information. Dec. 17, 2021 Added additional vulnerability and mitigation information; added section on guidance for developers; timeline. Dec. 16, 2021 Added | |
| | | | |
www.cybereason.com
|
|
| | | | | React2Shell vulnerability, tracked as CVE-2025-55182, recently discovered in React's Server Components, could allow for pre-authentication remote code execution. | |
| | | | |
www.cybereason.com
|
|
| | | A critical, unauthenticated remote code execution vulnerability, tracked as CVE-2025-32433, have been discovered in Erlang/OTP's SSH implementation. | ||