Aggregator
Infostealer campaign compromises 10 npm packages, targets devs
8 months 3 weeks ago
Ten npm packages were suddenly updated with malicious code yesterday to steal environment variables and other sensitive data from developers' systems. [...]
Bill Toulas
How CISA Cuts Impact Election Security
8 months 3 weeks ago
State and federal security experts weighed in on the impact that budgetary and personnel cuts to CISA will have on election security as a whole.
Alexander Culafi, Senior News Writer, Dark Reading
OpenAI Bumps Up Bug Bounty Reward to $100K in Security Update
8 months 3 weeks ago
The artificial intelligence research company previously had its maximum payout set at $20,000 before exponentially raising the reward.
Kristina Beek, Associate Editor, Dark Reading
Tonic Textual is now on the Databricks Marketplace: unstructured data, meet easy ingestion
8 months 3 weeks ago
Unlock and structure unstructured data with Tonic Textual on the Databricks Marketplace. Streamline AI workflows now.
The post Tonic Textual is now on the Databricks Marketplace: unstructured data, meet easy ingestion appeared first on Security Boulevard.
Expert Insights on Synthetic Data from the Tonic.ai Blog
PoC Code to Exploit the IngressNightmare Vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974)
8 months 3 weeks ago
PoC Code to Exploit the IngressNightmare Vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974)
Dark Web Informer - Cyber Threat Intelligence
Mozilla security advisory (AV25-170)
8 months 3 weeks ago
Canadian Centre for Cyber Security
More From Our Main Blog: GPU Device Plugins | Unveiling Risks in Kubernetes Workloads
8 months 3 weeks ago
Learn how to secure and leverage the full performance benefits of GPUs by mitigating undue risks in Kubernetes and GPU device plugins.
The post GPU Device Plugins | Unveiling Risks in Kubernetes Workloads appeared first on SentinelOne.
Yehonatan Bitton & Shaul Ben Hai
CVE-2008-2987 | Benja CMS 0.1 admin_edit_submenu.php cross site scripting (EDB-31954 / XFDB-43284)
8 months 3 weeks ago
A vulnerability was found in Benja CMS 0.1. It has been declared as problematic. This vulnerability affects unknown code of the file admin_edit_submenu.php. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2008-2987. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-49590 | Linux Kernel up to 5.18.14 sysctl_igmp_llm_reports information disclosure (Nessus ID 233382)
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.18.14. It has been declared as problematic. Affected by this vulnerability is the function sysctl_igmp_llm_reports. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2022-49590. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49567 | Linux Kernel up to 5.18.14 mpol_rebind_policy initialization (Nessus ID 233382)
8 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 5.18.14 and classified as critical. Affected by this vulnerability is the function mpol_rebind_policy. The manipulation leads to improper initialization.
This vulnerability is known as CVE-2022-49567. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-16154 | App::cpanminus 1.7044 on Perl signature verification (Nessus ID 233384)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in App::cpanminus 1.7044 on Perl. This issue affects some unknown processing. The manipulation leads to improper verification of cryptographic signature.
The identification of this vulnerability is CVE-2020-16154. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2022-36879 | Linux Kernel up to 5.18.14 net/xfrm/xfrm_policy.c xfrm_expand_policies denial of service (Nessus ID 233382)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.18.14. Affected by this issue is the function xfrm_expand_policies of the file net/xfrm/xfrm_policy.c. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2022-36879. Access to the local network is required for this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-36123 | Linux Kernel up to 5.18.12 Block Starting Symbol privilege escalation (SICK-2022-128 / Nessus ID 233382)
8 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 5.18.12. It has been declared as problematic. This vulnerability affects unknown code of the component Block Starting Symbol Handler. The manipulation leads to privilege escalation.
This vulnerability was named CVE-2022-36123. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-44730 | Apache Batik up to 1.16 SVG server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability was found in Apache Batik up to 1.16. It has been classified as critical. Affected is an unknown function of the component SVG Handler. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-44730. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-44729 | Oracle Business Process Management Suite 12.2.1.4.0 BPM Composer server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle Business Process Management Suite 12.2.1.4.0. This affects an unknown part of the component BPM Composer. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2022-44729. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-44729 | Oracle Business Intelligence Enterprise Edition 6.4.0.0.0/7.0.0.0.0/12.2.1.4.0 Presentation Services server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability was found in Oracle Business Intelligence Enterprise Edition 6.4.0.0.0/7.0.0.0.0/12.2.1.4.0. It has been rated as critical. This issue affects some unknown processing of the component Presentation Services. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2022-44729. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2022-44729 | Oracle Hyperion Financial Reporting 11.2.14.0.000 Installation server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle Hyperion Financial Reporting 11.2.14.0.000. Affected is an unknown function of the component Installation. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2022-44729. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-44729 | Oracle Database up to 19.20/21.11 Spatial/Graph server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability was found in Oracle Database up to 19.20/21.11. It has been declared as critical. This vulnerability affects unknown code of the component Spatial/Graph. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2022-44729. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-44729 | Oracle Middleware Common Libraries and Tools 12.2.1.4.0 Third Party server-side request forgery (Nessus ID 233387)
8 months 3 weeks ago
A vulnerability was found in Oracle Middleware Common Libraries and Tools 12.2.1.4.0. It has been rated as critical. This issue affects some unknown processing of the component Third Party. The manipulation leads to server-side request forgery.
The identification of this vulnerability is CVE-2022-44729. An attack has to be approached locally. There is no exploit available.
vuldb.com