A security flaw has been discovered in MaxSite CMS, a tool used to build and manage websites. This vulnerability allows attackers who do not have your site's login credentials to run harmful, unauthorized code on your site.To exploit the flaw, attackers send specially crafted requests to the CMS's installation endpoint, even after your site has ...
Continue reading
A critical security vulnerability has been identified in OpenEMR, a popular open-source electronic medical records software, affecting all versions released up to 8.2.0. This flaw exists in the software’s document category management feature, and could allow an attacker to run unauthorized, harmful commands on the server that hosts your OpenEMR ...
Continue reading
A security flaw has been found in N-able N-central, a tool many businesses use to remotely manage their servers, networks and other IT systems. This vulnerability lets attackers skip normal login checks by accessing the platform through an unusual, unsecured alternate path, which could let them take full control of N-central user accounts.This ...
Continue reading
A security vulnerability has been identified in IBM Langflow, a tool for building workflows and applications that some hosting clients may run on their accounts. The flaw is a code injection issue, which allows unauthenticated attackers (people who do not have valid login credentials for your Langflow instance) to run their own custom code on ...
Continue reading