๐จ CVE-2022-1321
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
๐@cveNotify
The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
๐@cveNotify
๐จ CVE-2022-1113
The Flower Delivery by Florist One WordPress plugin through 3.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)
๐@cveNotify
The Flower Delivery by Florist One WordPress plugin through 3.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups)
๐@cveNotify
๐จ CVE-2022-1971
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
๐@cveNotify
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
๐@cveNotify
๐จ CVE-2021-40897
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
๐@cveNotify
GitHub
SaveResults/split-html-to-chars.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40896
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
๐@cveNotify
GitHub
SaveResults/that-value.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40895
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
๐@cveNotify
GitHub
SaveResults/todo-regex.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2022-2068
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
๐@cveNotify
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
๐@cveNotify
๐จ CVE-2022-2217
Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
GitHub
Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
:rocket: An advanced url parser supporting git urls too. - Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
๐จ CVE-2022-0722
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
GitHub
Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
:rocket: An advanced url parser supporting git urls too. - Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
๐จ CVE-2021-40899
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.
๐@cveNotify
GitHub
SaveResults/repo-git-downloader.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40898
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.
๐@cveNotify
GitHub
SaveResults/js/scaffold-helper.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40897
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
๐@cveNotify
GitHub
SaveResults/split-html-to-chars.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40896
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
๐@cveNotify
GitHub
SaveResults/that-value.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2021-40895
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
๐@cveNotify
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
๐@cveNotify
GitHub
SaveResults/todo-regex.js at main ยท yetingli/SaveResults
Contribute to yetingli/SaveResults development by creating an account on GitHub.
๐จ CVE-2022-2216
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
๐@cveNotify
GitHub
Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
:rocket: An advanced url parser supporting git urls too. - Refactor codebase, upgrade dependencies ยท IonicaBizau/parse-url@21c72ab
๐จ CVE-2022-2207
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
๐@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
๐@cveNotify
๐จ CVE-2022-31913
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
๐@cveNotify
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
๐@cveNotify
๐จ CVE-2022-30177
Azure RTOS GUIX Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30178, CVE-2022-30179.
๐@cveNotify
Azure RTOS GUIX Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30178, CVE-2022-30179.
๐@cveNotify
๐จ CVE-2022-31912
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
๐@cveNotify
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
๐@cveNotify
GitHub
0525/online-tutor-portal-site/sql.md at main ยท mikeccltt/0525
Contribute to mikeccltt/0525 development by creating an account on GitHub.
๐จ CVE-2022-31911
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
๐@cveNotify
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
๐@cveNotify
๐จ CVE-2022-31910
Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
๐@cveNotify
Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
๐@cveNotify
GitHub
0525/xss.md at main ยท mikeccltt/0525
Contribute to mikeccltt/0525 development by creating an account on GitHub.