Aggregator
Are Airport IT Teams Feeling the Heat of Summer Travel?
10 months 3 weeks ago
Why is airport Wi-Fi so painfully slow? It’s a familiar complaint and a constant source of frustration. Whether they’re scanning, swiping, streaming, or checking in, travelers count on digital services to work flawlessly from curb to gate. As the summer travel season kicks into high gear, how can airport IT teams keep...
Anthony Cote
俄勒冈州成为第二个禁止出售精确地理位置数据的州
10 months 3 weeks ago
安全客
Он не лечит. Он требует. Новый робот учит чувствовать по-настоящему
10 months 3 weeks ago
Чтобы робот помог, нужно сначала помочь себе.
警企协同共育先锋!360反涉网犯罪训练营第六期圆满收官!
10 months 3 weeks ago
安全客
Apache InLong JDBC Vulnerability Enables Deserialization of Untrusted Data
10 months 3 weeks ago
A moderate-severity vulnerability, tracked as CVE-2025-27522, has been disclosed in Apache InLong, a popular data integration platform. The flaw, affecting versions 1.13.0 through 2.1.0, centers on the deserialization of untrusted data during JDBC (Java Database Connectivity) verification processing. This vulnerability is classified as a secondary mining bypass for the previously reported CVE-2024-26579, indicating that earlier […]
The post Apache InLong JDBC Vulnerability Enables Deserialization of Untrusted Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Anupriya
CVE-2022-34917 | Apache Kafka up to 2.8.1/3.0.1/3.1.1/3.2.2 Broker memory allocation
10 months 3 weeks ago
A vulnerability was found in Apache Kafka up to 2.8.1/3.0.1/3.1.1/3.2.2. It has been classified as problematic. Affected is an unknown function of the component Broker. The manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2022-34917. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-40955 | Apache InLong up to 1.2.x MySQL JDBC connection URL deserialization
10 months 3 weeks ago
A vulnerability classified as critical has been found in Apache InLong up to 1.2.x. Affected is an unknown function of the component MySQL JDBC connection URL Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2022-40955. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-35196 | TestLink 1.9.20 /lib/plan/planView.php cross-site request forgery
10 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in TestLink 1.9.20. Affected by this issue is some unknown functionality in the library /lib/plan/planView.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2022-35196. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-37883 | Aruba ClearPass Policy Manager up to 6.9.11/6.10.6 Web-based Management Interface privilege escalation (ARUBA-PSA-2022-013)
10 months 3 weeks ago
A vulnerability was found in Aruba ClearPass Policy Manager up to 6.9.11/6.10.6. It has been declared as very critical. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to privilege escalation.
This vulnerability was named CVE-2022-37883. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-28639 | HPE Integrated Lights-Out 5 2.71 privilege escalation
10 months 3 weeks ago
A vulnerability was found in HPE Integrated Lights-Out 5 2.71. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to privilege escalation.
The identification of this vulnerability is CVE-2022-28639. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-28638 | HPE Integrated Lights-Out 5 2.71 Local Privilege Escalation
10 months 3 weeks ago
A vulnerability classified as problematic was found in HPE Integrated Lights-Out 5 2.71. Affected by this vulnerability is an unknown functionality. The manipulation leads to Local Privilege Escalation.
This vulnerability is known as CVE-2022-28638. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-20015 | SmokePing up to 2.7.3-r1 on Gentoo initscript /var/lib/smokeping race condition
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in SmokePing up to 2.7.3-r1 on Gentoo. Affected by this issue is some unknown functionality in the library /var/lib/smokeping of the component initscript. The manipulation leads to race condition.
This vulnerability is handled as CVE-2016-20015. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2017-20148 | Logcheck up to 1.3.23.ebuild on Gentoo privilege escalation
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Logcheck up to 1.3.23.ebuild on Gentoo. This affects an unknown part. The manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2017-20148. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-38340 | Safe Software FME Server up to 2022.0.1.1 fmedataupload path traversal
10 months 3 weeks ago
A vulnerability has been found in Safe Software FME Server up to 2022.0.1.1 and classified as critical. This vulnerability affects unknown code of the component fmedataupload. The manipulation leads to path traversal.
This vulnerability was named CVE-2022-38340. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-41138 | Zutty up to 0.12 privilege escalation
10 months 3 weeks ago
A vulnerability was found in Zutty up to 0.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to privilege escalation.
This vulnerability is known as CVE-2022-41138. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-23694 | Aruba ClearPass Policy Manager up to 6.9.11/6.10.6 Web-based Management Interface sql injection (ARUBA-PSA-2022-013)
10 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Aruba ClearPass Policy Manager up to 6.9.11/6.10.6. This issue affects some unknown processing of the component Web-based Management Interface. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2022-23694. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-23695 | Aruba ClearPass Policy Manager up to 6.9.11/6.10.6 Web-based Management Interface sql injection (ARUBA-PSA-2022-013)
10 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Aruba ClearPass Policy Manager up to 6.9.11/6.10.6. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2022-23695. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2017-20147 | SmokePing up to 2.7.3-r1 on Gentoo ebuild denial of service
10 months 3 weeks ago
A vulnerability was found in SmokePing up to 2.7.3-r1 on Gentoo. It has been classified as problematic. Affected is an unknown function of the component ebuild. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2017-20147. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-34917 | Oracle Communications Elastic Charging Engine up to 12.0.0.7.0 Security denial of service
10 months 3 weeks ago
A vulnerability was found in Oracle Communications Elastic Charging Engine up to 12.0.0.7.0. It has been rated as critical. This issue affects some unknown processing of the component Security. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-34917. The attack may be initiated remotely. There is no exploit available.
vuldb.com