Aggregator
CVE-2022-49111 | Linux Kernel up to 5.17.2 hci_send_acl use after free (Nessus ID 237099)
CVE-2022-49137 | Linux Kernel up to 5.17.2 drm/amd/amdgpu/amdgpu_cs amdgpu_cs_fence_to_handle_ioctl reference count (Nessus ID 237099)
CVE-2022-49118 | Linux Kernel up to 5.10.110/5.15.33/5.16.19/5.17.2 drivers/pci/msi.c free_irq information disclosure (Nessus ID 237099)
CVE-2022-49060 | Linux Kernel up to 5.4.189/5.10.111/5.15.34/5.17.3 smc_pnet_find_ib null pointer dereference (Nessus ID 237099)
API接口深度发现的动态爬虫实现5 - API贪心发现
CVE-2022-49055 | Linux Kernel up to 5.17.3 kmalloc_array null pointer dereference (EUVD-2022-55149 / Nessus ID 237099)
CVE-2022-49044 | Linux Kernel up to 4.19.239/5.4.189/5.10.111/5.15.34/5.17.3 integrity_recalc tag_size memory corruption (Nessus ID 237099)
CVE-2025-2570 | Mattermost up to 9.11.11/10.5.2/10.6.x RestrictSystemAdmin Setting authorization (EUVD-2025-15178 / Nessus ID 237101)
CVE-2025-3446 | Mattermost up to 9.11.11/10.4.4/10.5.2/10.6.1 API authorization (EUVD-2025-15149 / Nessus ID 237102)
CVE-2025-4979 | GitLab Community Edition/Enterprise Edition up to 17.10.6/17.11.2/18.0.0 WebUI insufficient granularity of access control (Issue 524455 / EUVD-2025-16137)
CVE-2025-0993 | GitLab Community Edition/Enterprise Edition up to 17.10.6/17.11.2/18.0.0 allocation of resources (EUVD-2025-16148 / Nessus ID 237104)
CVE-2025-0605 | GitLab Community Edition/Enterprise Edition up to 17.10.6/17.11.2/18.0.0 Two-Factor Authentication Requirements weak authentication (EUVD-2025-16150 / Nessus ID 237105)
CVE-2025-0679 | GitLab Community Edition/Enterprise Edition up to 17.10.6/17.11.2/18.0.0 Email Address exposure of private personal information to an unauthorized actor (EUVD-2025-16149 / Nessus ID 237109)
CVE-2022-45063 | xterm up to 374 on Linux OSC 50 Response command injection (FEDORA-2022-681bbe67b6 / Nessus ID 237151)
CVE-2025-22233 | Vmware Spring Framework up to 5.3.42/6.0.27/6.1.19/6.2.6 disallowedFields Check input validation (EUVD-2025-15542 / Nessus ID 237119)
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
Shift left strategy creates heavy burden for developers
While 47% of organizations claim to have implemented shift left security strategies, many still struggle with execution gaps and security inefficiencies, according to Pynt. Of those who haven’t implemented shift left, half of them have no plans to do so at all. Shift left security gains momentum Since shift left security was introduced, companies have been trying to live up to its promise: identifying and addressing security issues earlier in the software development lifecycle, ideally … More →
The post Shift left strategy creates heavy burden for developers appeared first on Help Net Security.
CVE-2019-0230 | Apache Struts up to 2.5.20 Double OGNL Evaluation Attribute dynamically-determined object attributes (EDB-49068)
New infosec products of the week: May 23, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Anchore, Cyble, Outpost24, and ThreatMark. Outpost24 simplifies threat analysis with AI-enhanced summaries Outpost24 announced the addition of AI-enhanced summaries to the Digital Risk Protection (DRP) modules within its External Attack Surface Management (EASM) platform. With Outpost24’s DRP modules, organizations are able to identify, monitor, and protect against threats before they can be exploited. Cyble Titan strengthens endpoint security Cyble announced … More →
The post New infosec products of the week: May 23, 2025 appeared first on Help Net Security.