VMware fixes VM Escape Flaw

VMware fixes VM Escape Flaw

VMware addressed three vulnerabilities in multiple products, including a virtual machine escape flaw, tracked as CVE-2022-31705, that was exploited at the GeekPwn 2022. A working exploit for the CVE-2022-31705 vulnerability…
Path Traversal flaw in OWASP ESPI

Path Traversal flaw in OWASP ESPI

The Open Web Application Security Project (OWASP) has fixed a critical vulnerability in its Enterprise Security API (ESAPI) whose exploitation could have allowed threat actors to run path traversal attacks.…
ZOOM Fixes Path Traversal Flaws

ZOOM Fixes Path Traversal Flaws

Zoom has shipped patches for high severity vulnerabilities that expose enterprise users to remote code execution and command injection attacks with connection with Keybase connector client The network proxy page…

Apache Fixes In Wild Zero Day

The Apache Software Foundation has released a security patch to address a vulnerability in its HTTP Web Server project that has been actively exploited in the wild. Tracked as CVE-2021-41773,…