CVE-2022-28397 - **DISPUTED** Arbitrary File Upload in Ghost CMS v4.42.—What You Need to Know
---
Overview
A security advisory surfaced about CVE-2022-28397, which raises concerns about an arbitrary file upload vulnerability in the well-known Ghost CMS—specifically
CVE-2022-28346 - How Dictionary Expansion Opened Django to SQL Injection
Django, the famous Python web framework, is known for its robust protection against SQL injection. But in 2022, a serious vulnerability—CVE-2022-28346—was
CVE-2022-26854 - How a Weak Crypto Flaw in Dell PowerScale OneFS Opens the Door to Full System Takeover
---
Overview
In 2022, a critical vulnerability named CVE-2022-26854 was revealed in Dell PowerScale OneFS, previously known as Isilon, affecting its core cryptography. This
CVE-2022-26851 - Understanding the Predictable File Name Vulnerability in Dell PowerScale OneFS (v8.2.2-9.3.x)
---
Dell's PowerScale OneFS is a popular file storage platform in enterprise environments. But like any system, it's not immune to security
CVE-2022-23970 The update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter.
An attacker can create a specially-crafted update_json HTTP request that causes the update_json function to load a different file than it normally
Episode
00:00:00
00:00:00