Security
Headlines
HeadlinesLatestCVEs

Tag

#google

CVE-2022-25024: Analyzing PyPI package downloads — Python Packaging User Guide

The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.

CVE
#sql#web#google#dos#js#auth
FOG Forum 0.8 Cross Site Scripting

FOG Forum version 0.8 suffers from a cross site scripting vulnerability.

Fluent CMS 1.0.0 SQL Injection

Fluent CMS version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

FlightPath LMS 4.8.2 Insecure Direct Object Reference

FlightPath LMS version 4.8.2 suffers from an insecure direct object reference vulnerability.

FleetCart Laravel Ecommerce System 1.1.2 Insecure Settings

FleetCart Laravel Ecommerce System version 1.1.2 suffers from an ignored default credential vulnerability.

FixBook Repair Shop Management Tool 2.2 Hash Disclosure

FixBook Repair Shop Management Tool version 2.2 suffers from an information leakage vulnerability.

The Internet Is Turning Into a Data Black Box. An ‘Inspectability API’ Could Crack It Open

Unlike web browsers, mobile apps increasingly make it difficult or impossible to see what companies are really doing with your data. The answer? An inspectability API.

New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App

A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote." "The new version of XLoader is bundled inside a standard Apple disk image with the name OfficeNote.dmg," SentinelOne security researchers Dinesh Devadoss and Phil Stokes said in a Monday analysis. "The application