βΌ CVE-2021-40956 βΌ
π Read
via "National Vulnerability Database".
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34175 βΌ
π Read
via "National Vulnerability Database".
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33127 βΌ
π Read
via "National Vulnerability Database".
The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32554 βΌ
π Read
via "National Vulnerability Database".
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed credentials for accessing the productΓ’β¬β’s management interface. The password may be known outside Pure Storage and could be used on an affected system, if reachable, to execute arbitrary instructions with root privileges. No other Pure Storage products or services are affected. Remediation is available from Pure Storage via a self-serve Γ’β¬Εopt-inΓ’β¬οΏ½ patch, manual patch application or a software upgrade to an unaffected version of Purity software.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34195 βΌ
π Read
via "National Vulnerability Database".
Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34192 βΌ
π Read
via "National Vulnerability Database".
Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: Parameter choice, and Ontrack: SingleParameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33032 βΌ
π Read
via "National Vulnerability Database".
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.π Read
via "National Vulnerability Database".
βΌ CVE-2021-46824 βΌ
π Read
via "National Vulnerability Database".
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33024 βΌ
π Read
via "National Vulnerability Database".
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34171 βΌ
π Read
via "National Vulnerability Database".
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33026 βΌ
π Read
via "National Vulnerability Database".
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34178 βΌ
π Read
via "National Vulnerability Database".
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34211 βΌ
π Read
via "National Vulnerability Database".
A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34204 βΌ
π Read
via "National Vulnerability Database".
A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.π Read
via "National Vulnerability Database".
βΌ CVE-2022-32536 βΌ
π Read
via "National Vulnerability Database".
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34191 βΌ
π Read
via "National Vulnerability Database".
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34298 βΌ
π Read
via "National Vulnerability Database".
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."π Read
via "National Vulnerability Database".
βΌ CVE-2022-34300 βΌ
π Read
via "National Vulnerability Database".
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34328 βΌ
π Read
via "National Vulnerability Database".
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.π Read
via "National Vulnerability Database".
βΌ CVE-2022-34185 βΌ
π Read
via "National Vulnerability Database".
Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.π Read
via "National Vulnerability Database".
βΌ CVE-2022-33033 βΌ
π Read
via "National Vulnerability Database".
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.π Read
via "National Vulnerability Database".