🚨 CVE-2021-4156
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
🎖@cveNotify
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
🎖@cveNotify
🚨 CVE-2022-32532
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
🎖@cveNotify
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
🎖@cveNotify
🚨 CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
🎖@cveNotify
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
🎖@cveNotify
Blender Projects
Out-of-bounds memory access due to malformed HDR image file
**System Information**
Operating system: Windows-10-10.0.19044-SP0 64 Bits
Graphics card: Radeon RX 580 Series ATI Technologies Inc. 4.5.14761 Core Profile Context 21.10.3 30.0.13031.1001
**Blender Version**
Broken: version: 3.1.0 Alpha, branch: master,…
Operating system: Windows-10-10.0.19044-SP0 64 Bits
Graphics card: Radeon RX 580 Series ATI Technologies Inc. 4.5.14761 Core Profile Context 21.10.3 30.0.13031.1001
**Blender Version**
Broken: version: 3.1.0 Alpha, branch: master,…
🚨 CVE-2021-40642
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
🎖@cveNotify
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.
🎖@cveNotify
GitHub
Secure cookie test · textpattern/textpattern@211fab0
A flexible, elegant, fast and easy-to-use content management system written in PHP. - Secure cookie test · textpattern/textpattern@211fab0
🚨 CVE-2022-31303
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
🎖@cveNotify
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
🎖@cveNotify
GitHub
后台服务器组中存在XSS漏洞 · Issue #20 · maccmspro/maccms10
进入后台,点击视频-->服务器组-->添加, 在名称框插入payload1:<script>alert(1)</script> 在服务器组地址框插入payload2:<script>alert(2)</script> 在排序框插入payload3:<script>alert(3)</script> 在提示框插...
🚨 CVE-2022-31306
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
🎖@cveNotify
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
🎖@cveNotify
GitHub
SEGV njs_array.c:151:13 in njs_array_convert_to_slow_array · Issue #481 · nginx/njs
Environment OS : Linux ubuntu 5.13.0-27-generic #29~20.04.1-Ubuntu SMP Fri Jan 14 00:32:30 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux Commit : f65981b0b8fcf02d69a40bc934803c25c9f607ab Version : 0.7.2 ...
🚨 CVE-2022-31307
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
🎖@cveNotify
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
🎖@cveNotify
GitHub
Fixed Array.prototype.lastIndexOf() with unicode string as "this". · nginx/njs@eafe4c7
Previously, when lastIndexOf() was called with unicode string as "this"
argument and a negative "fromIndex" argument null-pointer dererence
might occur because n...
argument and a negative "fromIndex" argument null-pointer dererence
might occur because n...
🚨 CVE-2022-31897
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
🎖@cveNotify
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
🎖@cveNotify
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
🚨 CVE-2022-31266
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
🎖@cveNotify
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
🎖@cveNotify
🚨 CVE-2022-29272
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
🎖@cveNotify
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29271
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29269
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29270
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-23077
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
GitHub
fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
A habit tracker app which treats your goals like a Role Playing Game. - fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
🚨 CVE-2022-34011
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34013
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34012
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
🎖@cveNotify
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34170
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2021-41432
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
🎖@cveNotify
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
🎖@cveNotify
GitHub
Stored XSS in the Blog Content · Issue #88 · flatpressblog/flatpress
FlatPress 1.2.1 - Stored XSS in the Blog Content A stored Cross Site Scripting (XSS) vulnerability exists in version 1.2.1 of the FlatPress application that allows for arbitrary execution of JavaSc...
🚨 CVE-2022-34171
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-34172
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software