Aggregator
CVE-2025-29049 | MathLive up to 0.103.0 cross site scripting (GHSA-qwj6-q94f-8425)
CVE-2023-24057 | ca.uhn.hapi.fhir:org.hl7.fhir.core prior 5.6.92 ZIP Archive path traversal (GHSA-xr8x-pxm6-prjg)
CVE-2023-0468 | Linux Kernel up to 6.1 RC6 io_uring Subsystem io_uring/poll.c io_poll_check_events null pointer dereference
CVE-2023-0469 | Linux Kernel up to 6.1 RC6 io_uring Subsystem io_uring/filetable.c io_install_fixed_file integer underflow
CVE-2022-4092 | GitLab Enterprise Edition up to 15.6.0 README Page cross site scripting (Issue 383208)
CVE-2023-24493 | Tenable Tenable.sc Formula injection
CVE-2022-47073 | Small CRM 3.0 Create Ticket Page Subject cross site scripting
CVE-2022-47052 | Netgear Nighthawk R6220 1.1.0.112_1.0.1 cross site scripting
CVE-2005-1082 | Azerbaijan AzDGDating 1.1.0 view.php from sql injection (EDB-25374 / XFDB-20051)
CISO 视角下的十大漏洞管理最佳实践
Is Your Secrets Management Foolproof?
Are You Maximizing Your Secrets Management Strategy? Where technological advancements are rapidly reshaping business, cybersecurity is emerging as a crucial cornerstone of a successful organization. Are you leveraging robust secrets management to safeguard your organization, or are you leaving gaps that leave your sensitive data vulnerable? A Deep Dive Into Non-Human Identities (NHIs) and Secrets […]
The post Is Your Secrets Management Foolproof? appeared first on Entro.
The post Is Your Secrets Management Foolproof? appeared first on Security Boulevard.
Beyond the PCI DSS v4.0 Deadline: Feroot Ensures Compliance
The post Beyond the PCI DSS v4.0 Deadline: Feroot Ensures Compliance appeared first on Feroot Security.
The post Beyond the PCI DSS v4.0 Deadline: Feroot Ensures Compliance appeared first on Security Boulevard.
Visibility, Monitoring Key to Enterprise Endpoint Strategy
An Improved Detection Signature for the Kubernetes IngressNightmare Vulnerability
Wiz recently published a detailed analysis of a critical vulnerability in the NGINX Ingress admission controller—what they’ve dubbed IngressNightmare (CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, CVE-2025-24514). The vulnerability stems from insufficient input validation during configuration file processing, allowing an attacker to inject arbitrary code into the NGINX process. Wiz’s writeup is excellent and covers the technical nuances thoroughly, […]
The post An Improved Detection Signature for the Kubernetes IngressNightmare Vulnerability appeared first on Praetorian.
The post An Improved Detection Signature for the Kubernetes IngressNightmare Vulnerability appeared first on Security Boulevard.