How can I get a count of high risk vulnerabilities of web browsers? [closed]

Every month I’m reading about some zero-day vulnerability being exploited in Google Chrome. I’d like to roughly compare the situation with Firefox in some objective way. It’s ok if it does not fully capture everything (undisclosed vulnerab… Continue reading How can I get a count of high risk vulnerabilities of web browsers? [closed]

How to find the right CPE for your vendor and product [closed]

How do I find the right CPE for my vendor and product?
for example. I use org.hibernate » hibernate-core » 5.3.16.Final Maven dependency. However, when searching on NVD site(https://nvd.nist.gov/vuln/search) for hibernate-core or hibernate… Continue reading How to find the right CPE for your vendor and product [closed]

How GitHub Advisory assigns vulnerabilities to same components coming from different package managers?

I am trying to understand how GitHub Advisory filters vulnerabilities, particularly in the context of Bootstrap 3.3.7. In the National Vulnerability Database (NVD), the following vulnerabilities are reported for Bootstrap 3.3.7:
CVE-2019-8… Continue reading How GitHub Advisory assigns vulnerabilities to same components coming from different package managers?

Where to get images with vulnerabilities to test penetration tooling? [closed]

I had a request by some people in the Linux Users Group to show off metasploit. This is a product I’ve used, but I’m by no means an expert on.
Is there anything like an open source repository of images I can run in a virtual machine or the… Continue reading Where to get images with vulnerabilities to test penetration tooling? [closed]