๐จ CVE-2017-20073
A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cms.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cms.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
Exploit Database
Hindu Matrimonial Script - Authentication Bypass
Hindu Matrimonial Script - Authentication Bypass.. webapps exploit for PHP platform
๐จ CVE-2017-20072
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/generalsettings.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/generalsettings.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
Exploit Database
Hindu Matrimonial Script - Authentication Bypass
Hindu Matrimonial Script - Authentication Bypass.. webapps exploit for PHP platform
๐จ CVE-2017-20074
A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
๐@cveNotify
Vuldb
CVE-2017-20074 | Hindu Matrimonial Script newsletter1.php privileges management (EDB-41044 / EDB-41044)
A vulnerability was found in Hindu Matrimonial Script and classified as critical. This vulnerability is handled as CVE-2017-20074.
๐จ CVE-2022-25585
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
๐@cveNotify
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
๐@cveNotify
GitHub
Stored XSS exists ยท Issue #5 ยท union-home/unioncms
1.The problem is in system settings - basic settings - default settings - third party code write๏ผ<script>alert(1)</script> Save, open the home page and the XSS code will pop up The prob...
๐จ CVE-2022-2246
Prototype Pollution in GitHub repository clever/underscore.deep prior to 0.5.3.
๐@cveNotify
Prototype Pollution in GitHub repository clever/underscore.deep prior to 0.5.3.
๐@cveNotify
GitHub
Merge pull request from GHSA-8j79-hfj5-f2xm ยท Clever/underscore.deep@b5e109a
0.5.3
๐จ CVE-2022-2231
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.,2.
๐@cveNotify
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.,2.
๐@cveNotify
huntr.dev
NULL Pointer Dereference in vim
24.63K developers have been protected by securing vim. Read this report, and explore others to learn how you can also protect the world by earning cash and CVEs.
๐จ CVE-2021-3435
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
๐@cveNotify
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
๐@cveNotify
GitHub
L2CAP: Information leakage in le_ecred_conn_req()
### Impact
L2CAP: Information leakage in le_ecred_conn_req()
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information
If yo...
L2CAP: Information leakage in le_ecred_conn_req()
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information
If yo...
๐จ CVE-2021-3434
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm
๐@cveNotify
Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm
๐@cveNotify
GitHub
L2CAP: Stack based buffer overflow in le_ecred_conn_req()
### Impact
L2CAP: Stack based buffer overflow in le_ecred_conn_req
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information ...
L2CAP: Stack based buffer overflow in le_ecred_conn_req
### Patches
This has been fixed in:
- main #33305
- v2.5: #33419
- v2.4: #33418
- v1.14: TBD
### For more information ...
๐จ CVE-2021-3433
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp
๐@cveNotify
Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp
๐@cveNotify
GitHub
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Impact
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have ...
BT: Invalid channel map in CONNECT_IND results to Deadlock
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have ...
๐จ CVE-2021-3431
Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9
๐@cveNotify
Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9
๐@cveNotify
GitHub
BT: Assertion failure on repeated LL_FEATURE_REQ
### Impact
BT: Assertion failure on repeated LL_FEATURE_REQ
### Patches
This has been fixed in:
- main #33340
- v2.5: #33369
- v1.14: NA
### For more information
If you have any questio...
BT: Assertion failure on repeated LL_FEATURE_REQ
### Patches
This has been fixed in:
- main #33340
- v2.5: #33369
- v1.14: NA
### For more information
If you have any questio...
๐จ CVE-2021-3430
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr
๐@cveNotify
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr
๐@cveNotify
GitHub
BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQ
### Impact
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ.
### Patches
This has been fixed in:
- main: #33272
- v2.5: #33369
- v1.14: #33759
### For more information
If you h...
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ.
### Patches
This has been fixed in:
- main: #33272
- v2.5: #33369
- v1.14: #33759
### For more information
If you h...
๐จ CVE-2021-3432
Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4
๐@cveNotify
Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4
๐@cveNotify
GitHub
BT: Invalid interval in CONNECT_IND leads to Division by Zero
### Impact
Invalid interval in CONNECT_IND leads to Division by Zero
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have a...
Invalid interval in CONNECT_IND leads to Division by Zero
### Patches
This has been fixed in:
- main #33278
- v2.5: #33369
- v1.14: TBD
### For more information
If you have a...
๐จ CVE-2022-32974
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
๐@cveNotify
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
๐@cveNotify
Tenableยฎ
[R3] Nessus Version 10.2.0 Fixes Multiple Vulnerabilities
Nessus leverages third-party software to help provide underlying functionality. Several of the third-party components (zlib, expat, jQuery UI) were found to contain vulnerabilities, and updated versions have been made available by the providers. Additionallyโฆ
๐จ CVE-2022-33995
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
๐@cveNotify
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
๐@cveNotify
Devolutions
Devolutions | Productivity & security solutions for IT professionals
Discover one Devolutions ecosystem for remote connections, passwords, privileged access, and automation โ secure productivity for IT professionals worldwide.
๐จ CVE-2022-31884
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
๐@cveNotify
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
๐@cveNotify
Marval
Marval ITSM: Where people, process, and technology unite
Transform your IT and service support operations with Marval ITSM. Our integrated solutions, aligned with ITIL and ISO/IEC 20000, deliver cost reduction, standardization, ICT efficiency, and improved customer satisfaction. Partner with us to elevate yourโฆ
๐จ CVE-2022-25238
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
๐@cveNotify
Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.
๐@cveNotify
๐จ CVE-2022-24444
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
๐@cveNotify
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
๐@cveNotify
๐จ CVE-2021-41559
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
๐@cveNotify
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
๐@cveNotify
www.silverstripe.org
Security Releases
When potential security holes are discovered in SilverStripe's supported modules[https://docs.silverstripe.org/en/project_governance/supported_modules/], we produce security releases to ensure that you are able to promptly secure your SilverStripe websitesโฆ
๐จ CVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
๐@cveNotify
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
๐@cveNotify
GitHub
wuzhicms v4.1.0 statcode reflected xss vulnerability ยท Issue #183 ยท wuzhicms/wuzhicms
A xss vulnerability was discovered in WUZHI CMS 4.1.0 There is a reflected XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of /index....
๐จ CVE-2020-19896
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
๐@cveNotify
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
๐@cveNotify
GitHub
file inclusion vulnerability ยท Issue #36 ยท bg5sbk/MiniCMS
Require: PHP Version <5.3.4 magic_quotes_gpc=off 1. require $index_file $index_file = '../mc-files/posts/index/'.$post_old_state.'.php' $post_old_state = $data['state'] 2...