Security
Headlines
HeadlinesLatestCVEs

Source

Packet Storm

helloGTX Travel Portal CRM 1.6 Insecure Direct Object Reference

helloGTX Travel Portal CRM version 1.6 suffers from an insecure direct object reference vulnerability.

Packet Storm
#vulnerability#windows#google#auth#firefox
FlatApp Premium Admin Dashboard 1.0 SQL Injection

FlatApp Premium Admin Dashboard version 1.0 suffers from a remote SQL injection vulnerability.

Greeva 2.0 SQL Injection

Greeva version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Easy Web Portal 2.1.1 Cross Site Scripting

Easy Web Portal version 2.1.1 suffers from a cross site scripting vulnerability.

Easy Password Manager 1.1 Information Disclosure

Easy Password Manager version 1.1 suffers from an administrative information disclosure vulnerability.

Easy Member Pro 3.0 Insecure Direct Object Reference

Easy Member Pro version 3.0 suffers from an insecure direct object reference vulnerability.

Microsoft Windows Kernel Security Descriptor Use-After-Free

The Microsoft Windows Kernel CmDeleteLayeredKey may delete predefined tombstone keys, leading to security descriptor use-after-free.

Microsoft Windows Kernel Unsafe Reference

The Microsoft Windows Kernel may reference rolled-back transacted keys through differencing hives.

Microsoft Windows Kernel Unsafe Reference

The Microsoft Windows Kernel may reference unbacked layered keys through registry virtualization.