โผ CVE-2022-43927 โผ
๐ Read
via "National Vulnerability Database".
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-3172 โผ
๐ Read
via "National Vulnerability Database".
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24369 โผ
๐ Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-34164 โผ
๐ Read
via "National Vulnerability Database".
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.๐ Read
via "National Vulnerability Database".
โผ CVE-2020-19824 โผ
๐ Read
via "National Vulnerability Database".
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33948 โผ
๐ Read
via "National Vulnerability Database".
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-20803 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43929 โผ
๐ Read
via "National Vulnerability Database".
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-36775 โผ
๐ Read
via "National Vulnerability Database".
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 233576.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33926 โผ
๐ Read
via "National Vulnerability Database".
An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.1.6, 5.1.5, 5.1.4, 5.1.2, 5.1.1 5.1, 5.0rc3, 5.0rc2, 5.0rc1, 5.0.9, 5.0.8, 5.0.7, 5.0.6, 5.0.5, 5.0.4, 5.0.3, 5.0.2, 5.0.10, 5.0.1, 5.0, 4.3.9, 4.3.8, 4.3.7, 4.3.6, 4.3.5, 4.3.4, 4.3.3, 4.3.20, 4 allows attacker to access sensitive information via the RSS feed protlet.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-34182 โผ
๐ Read
via "National Vulnerability Database".
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-35261 โผ
๐ Read
via "National Vulnerability Database".
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-22868 โผ
๐ Read
via "National Vulnerability Database".
IBM Aspera Faspex 4.4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 244117.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0895 โผ
๐ Read
via "National Vulnerability Database".
The WP Coder รขโฌโ add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the รขโฌหidรขโฌโข parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33226 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40232 โผ
๐ Read
via "National Vulnerability Database".
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should not have access to due to improper permission controls. IBM X-Force ID: 235597.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33237 โผ
๐ Read
via "National Vulnerability Database".
Cross Site Scripting vulnerability in YMFE yapo v1.9.1 allows attacker to execute arbitrary code via the remark parameter of the interface edit page.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26020 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-32142 โผ
๐ Read
via "National Vulnerability Database".
Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_datastream::gets(char*, int) in /src/libraw/src/libraw_datastream.cpp.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-33391 โผ
๐ Read
via "National Vulnerability Database".
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-32163 โผ
๐ Read
via "National Vulnerability Database".
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.๐ Read
via "National Vulnerability Database".