๐จ CVE-2022-31031
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use STUN in their applications, either by: setting a STUN server in their account/media config in PJSUA/PJSUA2 level, or directly using `pjlib-util/stun_simple` API. A patch is available in commit 450baca which should be included in the next release. There are no known workarounds for this issue.
๐@cveNotify
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use STUN in their applications, either by: setting a STUN server in their account/media config in PJSUA/PJSUA2 level, or directly using `pjlib-util/stun_simple` API. A patch is available in commit 450baca which should be included in the next release. There are no known workarounds for this issue.
๐@cveNotify
GitHub
Merge pull request from GHSA-26j7-ww69-c4qj ยท pjsip/pjproject@450baca
PJSIP project. Contribute to pjsip/pjproject development by creating an account on GitHub.
๐จ CVE-2022-31876
netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
๐@cveNotify
netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
๐@cveNotify
๐จ CVE-2022-31875
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
๐@cveNotify
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
๐@cveNotify
๐จ CVE-2022-31874
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
๐@cveNotify
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
๐@cveNotify
๐จ CVE-2022-31873
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
๐@cveNotify
Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
๐@cveNotify
๐จ CVE-2022-21503
Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to Oracle Cloud Infrastructure accessible data. All affected customers were notified of CVE-2022-21503 by Oracle. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
๐@cveNotify
Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to Oracle Cloud Infrastructure accessible data. All affected customers were notified of CVE-2022-21503 by Oracle. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
๐@cveNotify
๐จ CVE-2022-25872
All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.
๐@cveNotify
All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Out-of-bounds Read in fast-string-search | CVE-2022-25872 | Snyk
Medium severity (5.3) Out-of-bounds Read in fast-string-search | CVE-2022-25872
๐จ CVE-2022-25871
All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
๐@cveNotify
All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Prototype Pollution in querymen | CVE-2022-25871 | Snyk
Medium severity (5.9) Prototype Pollution in querymen | CVE-2022-25871
๐จ CVE-2022-25856
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
๐@cveNotify
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
๐@cveNotify
Learn more about Go with Snyk Open Source Vulnerability Database
Directory Traversal in github.com/argoproj/argo-events/sensors/artifacts | CVE-2022-25856 | Snyk
High severity (7.5) Directory Traversal in github.com/argoproj/argo-events/sensors/artifacts | CVE-2022-25856
๐จ CVE-2022-25852
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.
๐@cveNotify
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.
๐@cveNotify
Learn more about rhel:7 with Snyk Open Source Vulnerability Database
Improper Preservation of Permissions in kernel-doc | CVE-2022-0330 | Snyk
High severity (7) Improper Preservation of Permissions in kernel-doc | CVE-2022-0330
๐จ CVE-2022-25345
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
๐@cveNotify
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in @discordjs/opus | CVE-2022-25345 | Snyk
High severity (7.5) Denial of Service (DoS) in @discordjs/opus | CVE-2022-25345
๐จ CVE-2022-22138
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in fast-string-search | CVE-2022-22138 | Snyk
High severity (7.5) Denial of Service (DoS) in fast-string-search | CVE-2022-22138
๐จ CVE-2022-21213
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
Snyk Vulnerability Database
Prototype Pollution in org.webjars.npm:mout | CVE-2022-21213 | Snyk
Fix high severity Prototype Pollution vulnerability affecting org.webjars.npm:mout package, versions [0,]
๐จ CVE-2021-40902
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
๐@cveNotify
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
๐@cveNotify
GitHub
Stored XSS in Index ยท Issue #57 ยท flatCore/flatCore-CMS
Describe the bug Cross Site Scripting (XSS) via save Exclude URLs To Reproduce Steps to reproduce the behavior: Login to flatcore CMS Click on 'Create new Page' after click '...
๐จ CVE-2022-0786
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users
๐@cveNotify
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users
๐@cveNotify
WPScan
KiviCare < 2.3.9 - Unauthenticated SQLi
See details on KiviCare < 2.3.9 - Unauthenticated SQLi CVE 2022-0786. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-0827
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
๐@cveNotify
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
๐@cveNotify
Wpscan
WPScan: WordPress Security
A WordPress vulnerability database for WordPress core security vulnerabilities, plugin vulnerabilities and theme vulnerabilities.
๐จ CVE-2022-0863
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
๐@cveNotify
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
๐@cveNotify
WPScan
WP SVG Icons <= 3.2.3 - Admin+ Remote Code Execution (RCE)
See details on WP SVG Icons <= 3.2.3 - Admin+ Remote Code Execution (RCE) CVE 2022-0863. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-0885
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
๐@cveNotify
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
๐@cveNotify
WPScan
Member Hero <= 1.0.9 - Unauthenticated RCE
See details on Member Hero <= 1.0.9 - Unauthenticated RCE CVE 2022-0885. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-1202
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
๐@cveNotify
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
๐@cveNotify
WPScan
WP-CRM <= 1.2.1 - CSV Injection
See details on WP-CRM <= 1.2.1 - CSV Injection CVE 2022-1202. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2022-22138
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
๐@cveNotify
Learn more about npm with Snyk Open Source Vulnerability Database
Denial of Service (DoS) in fast-string-search | CVE-2022-22138 | Snyk
High severity (7.5) Denial of Service (DoS) in fast-string-search | CVE-2022-22138
๐จ CVE-2022-21213
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
๐@cveNotify
Snyk Vulnerability Database
Prototype Pollution in org.webjars.npm:mout | CVE-2022-21213 | Snyk
Fix high severity Prototype Pollution vulnerability affecting org.webjars.npm:mout package, versions [0,]