‼ CVE-2023-1742 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in IBOS 4.5.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?r=report/api/getlist of the component Report Search. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-224630 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28755 ‼
📖 Read
via "National Vulnerability Database".
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1747 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-224635.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1753 ‼
📖 Read
via "National Vulnerability Database".
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1761 ‼
📖 Read
via "National Vulnerability Database".
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1754 ‼
📖 Read
via "National Vulnerability Database".
Improper Input Validation in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1759 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28756 ‼
📖 Read
via "National Vulnerability Database".
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1755 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1762 ‼
📖 Read
via "National Vulnerability Database".
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1760 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1258 ‼
📖 Read
via "National Vulnerability Database".
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28726 ‼
📖 Read
via "National Vulnerability Database".
Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28727 ‼
📖 Read
via "National Vulnerability Database".
Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.📖 Read
via "National Vulnerability Database".
👍1
🕴 Post-Quantum Satellite Protection Rockets Towards Reality 🕴
📖 Read
via "Dark Reading".
A successful multi-orbit cryptography test beamed quantum-agile data up to two different satellites and back down to Earth.📖 Read
via "Dark Reading".
Dark Reading
Post-Quantum Satellite Protection Rockets Towards Reality
A successful multi-orbit cryptography test beamed quantum-agile data up to two different satellites and back down to Earth.
‼ CVE-2023-1774 ‼
📖 Read
via "National Vulnerability Database".
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1771 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224672.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1775 ‼
📖 Read
via "National Vulnerability Database".
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1773 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration File Handler. The manipulation leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224674 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1770 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affected by this vulnerability is the function get_scale of the file Master.php. The manipulation of the argument perc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224671.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-1772 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part of the component Diagram Type Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224673 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".