‼ CVE-2022-4740 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216776.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4736 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument the_title leads to cross site scripting. The attack may be launched remotely. The name of the patch is 62339b2ec445692c710b804bdf07aef4bd247ff7. It is recommended to apply a patch to fix this issue. VDB-216770 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-4279 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 is able to address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2020-36630 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the argument limit/offset leads to sql injection. Upgrading to version 14.0.5.21 is able to address this issue. The name of the patch is f1a9eea2dfff30fb99d825bac194a676a82b9ec8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216771.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24119 ‼
📖 Read
via "National Vulnerability Database".
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24118 ‼
📖 Read
via "National Vulnerability Database".
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37313 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37311 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37312 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24120 ‼
📖 Read
via "National Vulnerability Database".
Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29852 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-31469 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24116 ‼
📖 Read
via "National Vulnerability Database".
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44758 ‼
📖 Read
via "National Vulnerability Database".
Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44855 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37309 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37307 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37310 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45467 ‼
📖 Read
via "National Vulnerability Database".
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44854 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29853 ‼
📖 Read
via "National Vulnerability Database".
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.📖 Read
via "National Vulnerability Database".