Bulletins d'actualité

De Docaposte Cyberdéfense
Aller à : navigation, rechercher

Classification


Logo-anssi-seul.png

Publication de l'Agence National de la Sécurité des Systèmes d'Information

Les avis sont des documents faisant état de vulnérabilités et des moyens de s'en prémunir



Doc.png

[webapps] OpenEMR 7.0.2 - Arbitrary File Read
OpenEMR 7.0.2 - Arbitrary File Read

Doc.png

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

Doc.png

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection
Drupal Core 10.5.5 - Error-Based SQL Injection

Doc.png

[webapps] WordPress OrderConvo 14 - Path Traversal
WordPress OrderConvo 14 - Path Traversal

Doc.png

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution
Notepad++ 8.9.6 - Arbitrary Code Execution

Doc.png

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting
YAMCS yamcs-core 5.12.7 - No Rate Limiting

Doc.png

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration
YAMCS yamcs-core 5.12.7 - User Enumeration

Doc.png

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection
YAMCS yamcs-core 5.12.7 - LDAP Injection

Doc.png

[remote] Microsoft - NTLMv2 Hash Capture
Microsoft - NTLMv2 Hash Capture

Doc.png

[webapps] MikroORM 7.0.13 - SQL Injection
MikroORM 7.0.13 - SQL Injection

Doc.png

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion
Prodigy Commerce 3.3.0 - Local File Inclusion

Doc.png

[webapps] Langflow 1.3.0 - Remote Code Execution
Langflow 1.3.0 - Remote Code Execution

Doc.png

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Doc.png

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Doc.png

[local] ZTE Routers - Unauthenticated Denial of Service
ZTE Routers - Unauthenticated Denial of Service