Author: Angelo Barbosa

CVE-2022-2232 | Keycloak prior 23.0.1 Login UsernameForm ldap injection

A vulnerability classified as problematic has been found in Keycloak. This affects an unknown part of the component Login. The manipulation of the argument UsernameForm leads to ldap injection. This vulnerability is uniquely identified as CVE-2022-2232. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-3741 | NEC DT900/DT900S os command injection

A vulnerability was found in NEC DT900 and DT900S. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to os command injection. This vulnerability is handled as CVE-2023-3741. The attack needs to be done within the local network. There is no exploit...

Read More

CVE-2022-42540 | Google Android Privilege Escalation

A vulnerability was found in Google Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to Privilege Escalation. This vulnerability is known as CVE-2022-42540. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2022-42538 | Google Android Privilege Escalation

A vulnerability was found in Google Android. It has been classified as problematic. Affected is an unknown function. The manipulation leads to Privilege Escalation. This vulnerability is traded as CVE-2022-42538. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-44383 | October CMS up to 3.5.1 Media Manager cross site scripting (GHSA-rvx8-p3xp-fj3p)

A vulnerability was found in October CMS up to 3.5.1 and classified as problematic. This issue affects some unknown processing of the component Media Manager. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2023-44383. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More