CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, mwEmbed (also distributed as html5lib), that allow remote, unauthenticated attackers…
A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read arbitrary files accessible to the service account. Tracked…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
An external control of file name vulnerability in Citrix NetScaler ADC and Gateway allowing unauthenticated arbitrary file read when management access is…