Security
Headlines
HeadlinesLatestCVEs

Tag

#vulnerability

Emergency Ambulance Hiring Portal 1.0 Insecure Settings

Emergency Ambulance Hiring Portal version 1.0 suffers from an ignored default credential vulnerability.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
Car Washing Management System 1.0 Insecure Settings

Car Washing Management System version 1.0 suffers from an ignored default credential vulnerability.

Bus Pass Management System 1.0 Insecure Settings

Bus Pass Management System version 1.0 suffers from an ignored default credential vulnerability.

BP Monitoring Management System 1.0 Insecure Settings

BP Monitoring Management System version 1.0 suffers from an ignored default credential vulnerability.

Auto/Taxi Stand Management System 1.0 PHP Code Injection

Auto/Taxi Stand Management System version 1.0 suffers from a php code injection vulnerability.

Art Gallery Management System 1.0 Insecure Settings

Art Gallery Management System version 1.0 suffers from an ignored default credential vulnerability.

Red Hat Security Advisory 2024-6657-03

Red Hat Security Advisory 2024-6657-03 - Migration Toolkit for Runtimes 1.2.7 release Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link in the References section.

Apple Vision Pro Vulnerability Exposed Virtual Keyboard Inputs to Attackers

Details have emerged about a now-patched security flaw impacting Apple's Vision Pro mixed reality headset that, if successfully exploited, could allow malicious attackers to infer data entered on the device's virtual keyboard. The attack, dubbed GAZEploit, has been assigned the CVE identifier CVE-2024-40865. "A novel attack that can infer eye-related biometrics from the avatar image to

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw

Malicious actors are likely leveraging publicly available proof-of-concept (PoC) exploits for recently disclosed security flaws in Progress Software WhatsUp Gold to conduct opportunistic attacks. The activity is said to have commenced on August 30, 2024, a mere five hours after a PoC was released for CVE-2024-6670 (CVSS score: 9.8) by security researcher Sina Kheirkhah of the Summoning Team, who