Security
Headlines
HeadlinesLatestCVEs

Headline

Apache HTTP Server update fails to squash path traversal, RCE bugs

Web admins told to upgrade (once again) to latest version

PortSwigger

Related news

CVE-2021-30628: Stable Channel Update for Desktop

Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.

WordPress 3DPrint Lite 1.9.1.4 Shell Upload

WordPress 3DPrint Lite plugin version 1.9.1.4 suffers from a remote shell upload vulnerability.

CVE-2021-36872: wordpress-popular-posts/changelog.md at master · cabrerahector/wordpress-popular-posts

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].

CVE-2021-30544: Stable Channel Update for Desktop

Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30551: Stable Channel Update for Desktop

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30545: Stable Channel Update for Desktop

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

PortSwigger: Latest News

We’re going teetotal: It’s goodbye to The Daily Swig