CVE-2022-1338 The Easily Generate Rest API Url WordPress plugin has settings that allow high privilege users to perform XSS attacks.
When creating a new REST API, the plugin allows for the setting of the allowed_origins capability, which if left empty defaults to the setting
CVE-2022-30286 - How a Simple Flaw in PyScript Demonstrator Leaked Your Python Code
In 2022, a serious vulnerability—CVE-2022-30286—was discovered in pyscriptjs, also known as PyScript Demonstrator. This flaw opened the door for attackers to
CVE-2022-29167 - How a Regex DoS Bug in Hawk’s Host Parsing Could Kill Your API Performance
---
Hawk is a popular Node.js library used in many APIs and services for HTTP authentication. It aims to provide strong security with simple usage.
CVE-2022-20777 - Cisco NFVIS VM Escape - How Attackers Break Out From Virtual Machines
Virtualization is supposed to lock things down. It lets us run several virtual machines (VMs) on one piece of hardware, keeping them safely apart. But
CVE-2022-29824 libxml2 before 2.9.14 has a bug that can lead to memory write issues. This can affect applications that use libxml2.
This issue was originally reported in the LibXmlConvert RSS feed, where an XML file over 2 GB was opened. Thanks to the overwhelming response, the
Episode
00:00:00
00:00:00