โผ CVE-2021-4327 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initialize_typed_array_from_array_buffer in the library Userland/Libraries/LibJS/Runtime/TypedArray.cpp. The manipulation leads to integer overflow. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The name of the patch is f6c6047e49f1517778f5565681fb64750b14bf60. It is recommended to apply a patch to fix this issue. VDB-222074 is the identifier assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
๐ด Without FIDO2, MFA Falls Short ๐ด
๐ Read
via "Dark Reading".
The open authentication standard addresses existing multifactor authentication security vulnerabilities.๐ Read
via "Dark Reading".
Dark Reading
Without FIDO2, MFA Falls Short
The open authentication standard addresses existing multifactor authentication security vulnerabilities.
โผ CVE-2022-45804 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1115 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45068 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23974 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40198 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet รขโฌโ For WooCommerce plugin <= 1.3.24 leading to plugin settings change.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1064 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection.This issue affects Weighbridge Automation Software: before 1.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1117 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23973 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page รขโฌโ Contact People plugin <= 3.7.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1116 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23984 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu รขโฌโ circle floating menu plugin <= 3.0.1 leading to form deletion.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46797 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings change.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-38468 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin รขโฌโ NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.๐ Read
via "National Vulnerability Database".
๐ด CISA: ZK Java Framework RCE Flaw Under Active Exploit ๐ด
๐ Read
via "Dark Reading".
The flaw, which drew attention in October when it was found in ConnectWise products, could pose a significant risk to the supply chain if not patched immediately.๐ Read
via "Dark Reading".
Dark Reading
CISA: ZK Java Framework RCE Flaw Under Active Exploit
The flaw, which drew attention in October when it was found in ConnectWise products, could pose a significant risk to the supply chain if not patched immediately.
โผ CVE-2023-24755 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25222 โผ
๐ Read
via "National Vulnerability Database".
A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46806 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25544 โผ
๐ Read
via "National Vulnerability Database".
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24756 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46798 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.๐ Read
via "National Vulnerability Database".