FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

CISA Issues Warning on Active Exploitation of ZK Java Web Framework Vulnerability

By: Ravie Lakshmanan β€” February 28th 2023 at 06:42
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasΒ addedΒ a high-severity flaw affecting the ZK Framework to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Tracked asΒ CVE-2022-36537Β (CVSS score: 7.5), the issue impacts ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1, and allows threat actors to retrieve sensitive
☐ β˜† βœ‡ The Hacker News

Researchers Disclose Critical RCE Vulnerability Affecting Quarkus Java Framework

By: Ravie Lakshmanan β€” December 1st 2022 at 11:44
A critical security vulnerability has been disclosed in the Quarkus Java framework that could be potentially exploited to achieve remote code execution on affected systems. Tracked asΒ CVE-2022-4116Β (CVSS score: 9.8), the shortcoming could be trivially abused by a malicious actor without any privileges. "The vulnerability is found in the Dev UI Config Editor, which is vulnerable to drive-by
❌