Severity Medium Analysis Summary CVE-2021-22697, CVE-2021-22698 When a malicious SSD file is uploaded and improperly parsed, an attacker could cause a use-after-free condition or stack-based buffer […]
Severity Medium Analysis Summary CVE-2020-9050 Metasys Reporting Engine (MRE) Web Services does not properly sanitize pathname elements that can resolve to a location that is outside […]
Severity Medium Analysis Summary CVE-2021-1351 Cisco Webex Meetings is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based interface. A remote […]
Severity Medium Analysis Summary CVE-2021-26559 Apache Airflow could allow a remote authenticated attacker to obtain sensitive information, caused by improper access control on Configurations Endpoint for […]
Severity Medium Analysis Summary CVE-2021-1372 Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow a local authenticated attacker to obtain sensitive information, […]
Severity Medium Analysis Summary CVE-2021-23839 OpenSSL could provide weaker than expected security, caused by incorrect SSLv2 rollback protection that allows for the inversion of the logic […]
Severity Medium Analysis Summary AZORult is a Trojan stealer that collects various data on infected computers and sends it to the C&C server, including browser history, […]
Severity High Analysis Summary An uptick in phishing campaigns is seen, targeting multiple organizations, including financial institutions, by abusing the ngrok platform. Ngrok is a cross-platform […]
Severity Medium Analysis Summary CVE-2020-4956 IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows […]