‼ CVE-2022-4724 ‼
📖 Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4722 ‼
📖 Read
via "National Vulnerability Database".
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4721 ‼
📖 Read
via "National Vulnerability Database".
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36626 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 4528d4f855dbbf24e9fc12a162fda84ce3bedc2f. It is recommended to apply a patch to fix this issue. VDB-216738 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4694 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4725 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils of the file aws-android-sdk-core/src/main/java/com/amazonaws/util/XpathUtils.java of the component XML Parser. The manipulation leads to server-side request forgery. Upgrading to version 2.59.1 is able to address this issue. The name of the patch is c3e6d69422e1f0c80fe53f2d757b8df97619af2b. It is recommended to upgrade the affected component. The identifier VDB-216737 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4734 ‼
📖 Read
via "National Vulnerability Database".
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository usememos/memos prior to 0.9.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4728 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. VDB-216742 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4729 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216743.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4719 ‼
📖 Read
via "National Vulnerability Database".
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4723 ‼
📖 Read
via "National Vulnerability Database".
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4733 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4691 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4727 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getNotes of the file api/src/main/java/org/openmrs/module/appointmentscheduling/AppointmentRequest.java of the component Notes Handler. The manipulation of the argument notes leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.17.0 is able to address this issue. The name of the patch is 2ccbe39c020809765de41eeb8ee4c70b5ec49cc8. It is recommended to upgrade the affected component. The identifier VDB-216741 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-4730 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216744.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4720 ‼
📖 Read
via "National Vulnerability Database".
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4732 ‼
📖 Read
via "National Vulnerability Database".
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4726 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-216739.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4695 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4767 ‼
📖 Read
via "National Vulnerability Database".
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.📖 Read
via "National Vulnerability Database".
⚠ Critical “10-out-of-10” Linux kernel SMB hole – should you worry? ⚠
📖 Read
via "Naked Security".
It's serious, it's critical, and you could call it severe... but in HHGttG terminology, it's probably "mostly harmless".📖 Read
via "Naked Security".
Sophos News
Naked Security – Sophos News
👍2