🚨 CVE-2022-24444
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
🎖@cveNotify
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
🎖@cveNotify
🚨 CVE-2021-41559
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
🎖@cveNotify
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
🎖@cveNotify
www.silverstripe.org
Security Releases
When potential security holes are discovered in SilverStripe's supported modules[https://docs.silverstripe.org/en/project_governance/supported_modules/], we produce security releases to ensure that you are able to promptly secure your SilverStripe websites…
🚨 CVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
🎖@cveNotify
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
🎖@cveNotify
GitHub
wuzhicms v4.1.0 statcode reflected xss vulnerability · Issue #183 · wuzhicms/wuzhicms
A xss vulnerability was discovered in WUZHI CMS 4.1.0 There is a reflected XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of /index....
🚨 CVE-2020-19896
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
🎖@cveNotify
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
🎖@cveNotify
GitHub
file inclusion vulnerability · Issue #36 · bg5sbk/MiniCMS
Require: PHP Version <5.3.4 magic_quotes_gpc=off 1. require $index_file $index_file = '../mc-files/posts/index/'.$post_old_state.'.php' $post_old_state = $data['state'] 2...
🚨 CVE-2017-12562
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
🎖@cveNotify
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
🎖@cveNotify
GitHub
Heap buffer overflows in `psf_binheader_writef` in 1.0.28 and later · Issue #292 · libsndfile/libsndfile
Case 's' only enlarges the buffer by 16 bytes instead of size bytes. This issue had originally reported by funute against openmpt123 (see https://bugs.openmpt.org/view.php?id=974 )....
🚨 CVE-2021-4156
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
🎖@cveNotify
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
🎖@cveNotify
🚨 CVE-2022-32532
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
🎖@cveNotify
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
🎖@cveNotify
🚨 CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
🎖@cveNotify
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
🎖@cveNotify
Blender Projects
Out-of-bounds memory access due to malformed HDR image file
**System Information**
Operating system: Windows-10-10.0.19044-SP0 64 Bits
Graphics card: Radeon RX 580 Series ATI Technologies Inc. 4.5.14761 Core Profile Context 21.10.3 30.0.13031.1001
**Blender Version**
Broken: version: 3.1.0 Alpha, branch: master,…
Operating system: Windows-10-10.0.19044-SP0 64 Bits
Graphics card: Radeon RX 580 Series ATI Technologies Inc. 4.5.14761 Core Profile Context 21.10.3 30.0.13031.1001
**Blender Version**
Broken: version: 3.1.0 Alpha, branch: master,…
🚨 CVE-2021-40642
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
🎖@cveNotify
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
🎖@cveNotify
GitHub
Secure cookie test · textpattern/textpattern@211fab0
A flexible, elegant, fast and easy-to-use content management system written in PHP. - Secure cookie test · textpattern/textpattern@211fab0
🚨 CVE-2022-31303
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
🎖@cveNotify
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
🎖@cveNotify
GitHub
后台服务器组中存在XSS漏洞 · Issue #20 · maccmspro/maccms10
进入后台,点击视频-->服务器组-->添加, 在名称框插入payload1:<script>alert(1)</script> 在服务器组地址框插入payload2:<script>alert(2)</script> 在排序框插入payload3:<script>alert(3)</script> 在提示框插...
🚨 CVE-2022-31306
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
🎖@cveNotify
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
🎖@cveNotify
GitHub
SEGV njs_array.c:151:13 in njs_array_convert_to_slow_array · Issue #481 · nginx/njs
Environment OS : Linux ubuntu 5.13.0-27-generic #29~20.04.1-Ubuntu SMP Fri Jan 14 00:32:30 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux Commit : f65981b0b8fcf02d69a40bc934803c25c9f607ab Version : 0.7.2 ...
🚨 CVE-2022-31307
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
🎖@cveNotify
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
🎖@cveNotify
GitHub
Fixed Array.prototype.lastIndexOf() with unicode string as "this". · nginx/njs@eafe4c7
Previously, when lastIndexOf() was called with unicode string as "this"
argument and a negative "fromIndex" argument null-pointer dererence
might occur because n...
argument and a negative "fromIndex" argument null-pointer dererence
might occur because n...
🚨 CVE-2022-31897
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
🎖@cveNotify
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
🎖@cveNotify
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
🚨 CVE-2022-31266
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
🎖@cveNotify
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
🎖@cveNotify
🚨 CVE-2022-29272
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
🎖@cveNotify
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29271
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29269
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29270
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-23077
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
GitHub
fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
A habit tracker app which treats your goals like a Role Playing Game. - fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
🚨 CVE-2022-34011
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34013
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客