Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Siemens Simcenter Femap NEU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required

Read More
NewsSecurity Vulnerabilities

Vinchin Backup and Recovery MySQL Server Use of Hard-coded Credentials Authentication Bypass Vulnerability [CVE-2022-2139]

CVE number = CVE-2022-2139 This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery.

Read More
NewsSecurity Vulnerabilities

Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities [CVE-2022-20812 and CVE-2022-20813]

CVE numbers = CVE-2022-20812 and CVE-2022-20813 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway

Read More
NewsSecurity Vulnerabilities

Anker Eufy Homebase 2 mips_collector appsrv_server use-after-free vulnerability [CVE-2022-21806]

CVE number = CVE-2022-21806 A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A

Read More
NewsSecurity Vulnerabilities

Apache HTTPD Server ap_escape_html2 Integer Overflow Remote Code Execution Vulnerability [CVE-2022-22721]

CVE number – CVE-2022-22721 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apache HTTPD Server.

Read More
NewsSecurity Vulnerabilities

(Pwn2Own) Prosys OPC UA SDK for Java OPC UA Messages Resource Exhaustion Denial-of-Service Vulnerability [CVE-2022-30551]

CVE number = CVE-2022-30551 This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Prosys OPC

Read More
NewsSecurity Vulnerabilities

Cisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability [CVE-2022-20828]

CVE number – CVE-2022-20828 A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER

Read More
NewsSecurity Vulnerabilities

Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability [CVE-2022-20802]

CVE number – CVE-2022-20802 A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an

Read More
NewsSecurity Vulnerabilities

Spring Framework remote code execution [CVE-2022-22965]

CVE number = CVE-2022-22965 Spring Framework could allow a remote attacker to execute arbitrary code on the system, caused by

Read More
NewsSecurity Vulnerabilities

Microsoft Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability [CVE-2022-30149]

CVE number – CVE-2022-30149 Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by

Read More