Packet Tide has fixed a group of XSS vulnerabilities and an open HTTP redirection bug in its ExpressionEngine content management system, some of which could give an attacker admin access.
The federal government's vulnerability disclosure policy platform has taken in more than 1,300 unique valid bug reports in its first 18 months.
A critical flaw (CVE-2023-29017) has been patched in the VM2 sandbox that runs on Node.js.
Version 8 of libcurl has been released, patching six vulnerabilities, including an authentication bypass.
An update for the Node.js framework includes fixes for DNS rebinding and HTTP smuggling vulnerabilities.