‼ CVE-2022-45297 ‼
📖 Read
via "National Vulnerability Database".
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-0454 ‼
📖 Read
via "National Vulnerability Database".
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-42972 ‼
📖 Read
via "National Vulnerability Database".
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23928 ‼
📖 Read
via "National Vulnerability Database".
reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to authorization bypass. Applications relying on JWS claims assertion to enforce security boundaries may be vulnerable to privilege escalation. This issue has been patched in version 0.8.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-47770 ‼
📖 Read
via "National Vulnerability Database".
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34400 ‼
📖 Read
via "National Vulnerability Database".
Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45095 ‼
📖 Read
via "National Vulnerability Database".
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of service, information disclosure, and data deletion.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0607 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-22786 ‼
📖 Read
via "National Vulnerability Database".
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP* and BMEH*) (Versions prior to SV3.20), Modicon MC80 (BMKC80) (Versions prior to V1.6), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum MDI (171CBU*) (Versions prior to V2.3), Legacy Modicon Quantum (All Versions)📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23630 ‼
📖 Read
via "National Vulnerability Database".
Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to `res.render`.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45097 ‼
📖 Read
via "National Vulnerability Database".
Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-4206 ‼
📖 Read
via "National Vulnerability Database".
A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report📖 Read
via "National Vulnerability Database".
‼ CVE-2022-25916 ‼
📖 Read
via "National Vulnerability Database".
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-47769 ‼
📖 Read
via "National Vulnerability Database".
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45096 ‼
📖 Read
via "National Vulnerability Database".
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-31902 ‼
📖 Read
via "National Vulnerability Database".
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23846 ‼
📖 Read
via "National Vulnerability Database".
Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS tunneling protocol (GPTv1-U) messages, a protocol payload with any extension header length set to zero causes an infinite loop. The affected process becomes immediately unresponsive, resulting in denial of service and excessive resource consumption. CVSS3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0587 ‼
📖 Read
via "National Vulnerability Database".
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24324 ‼
📖 Read
via "National Vulnerability Database".
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34458 ‼
📖 Read
via "National Vulnerability Database".
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-34459 ‼
📖 Read
via "National Vulnerability Database".
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get applicable driver component. A local malicious user could potentially exploit this vulnerability leading to malicious payload execution.📖 Read
via "National Vulnerability Database".