‼ CVE-2015-10064 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in VictorFerraresi pokemon-database-php. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The name of the patch is dd0e1e6cdf648d6a3deff441f515bcb1d7573d68. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218455.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22624 ‼
📖 Read
via "National Vulnerability Database".
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-23739 ‼
📖 Read
via "National Vulnerability Database".
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain access to and modify most organization-level resources that are not tied to a repository regardless of granted permissions, such as users and organization-wide projects. Resources associated with repositories were not impacted, such as repository file content, repository-specific projects, issues, or pull requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7.1 and was fixed in versions 3.3.16, 3.4.11, 3.5.8, 3.6.4, 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23749 ‼
📖 Read
via "National Vulnerability Database".
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4891 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function to_plain of the file lib/sisimai/string.rb. The manipulation leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. Upgrading to version 4.25.14p12 is able to address this issue. The name of the patch is 51fe2e6521c9c02b421b383943dc9e4bbbe65d4e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218452.📖 Read
via "National Vulnerability Database".
‼ CVE-2015-10063 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in saemorris TheRadSystem and classified as critical. This issue affects the function redirect of the file _login.php. The manipulation of the argument user/pass leads to sql injection. The attack may be initiated remotely. The name of the patch is bfba26bd34af31648a11af35a0bb66f1948752a6. It is recommended to apply a patch to fix this issue. The identifier VDB-218453 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40704 ‼
📖 Read
via "National Vulnerability Database".
A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite.📖 Read
via "National Vulnerability Database".
‼ CVE-2006-20001 ‼
📖 Read
via "National Vulnerability Database".
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-3650 ‼
📖 Read
via "National Vulnerability Database".
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-47853 ‼
📖 Read
via "National Vulnerability Database".
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.📖 Read
via "National Vulnerability Database".
‼ CVE-2015-10062 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to address this issue. The name of the patch is 50d65f45d3f5be5d1fbff2e45ac5cec075f07d42. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218451.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22875 ‼
📖 Read
via "National Vulnerability Database".
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-37436 ‼
📖 Read
via "National Vulnerability Database".
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-36760 ‼
📖 Read
via "National Vulnerability Database".
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-39195 ‼
📖 Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-22727 ‼
📖 Read
via "National Vulnerability Database".
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22730 ‼
📖 Read
via "National Vulnerability Database".
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions It was possible to put the same line item multiple times in the cart using the AP. The Cart Validators checked the line item's individuality and the user was able to bypass quantity limits in sales. This problem has been fixed with version 6.4.18.1. Users on major versions 6.1, 6.2, and 6.3 may also obtain this fix via a plugin.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0296 ‼
📖 Read
via "National Vulnerability Database".
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be considered as still vulnerable to the same type of vulnerability. The health checks on etcd grpc-proxy do not contain sensitive data (only metrics data), therefore the potential impact related to this vulnerability is minimal. The CVE-2023-0296 has been assigned to this issue to track the permanent fix in the etcd component.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-36647 ‼
📖 Read
via "National Vulnerability Database".
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted operating system attacking a secure enclave such as SGX or the TrustZone secure world) to recover the private keys used in RSA.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-40319 ‼
📖 Read
via "National Vulnerability Database".
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-2251 ‼
📖 Read
via "National Vulnerability Database".
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.📖 Read
via "National Vulnerability Database".