🚨 CVE-2022-29271
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29269
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-29270
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
🎖@cveNotify
GitHub
GitHub - sT0wn-nl/CVEs: The following is a list of my collected CVE's
The following is a list of my collected CVE's. Contribute to sT0wn-nl/CVEs development by creating an account on GitHub.
🚨 CVE-2022-23077
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
🎖@cveNotify
GitHub
fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
A habit tracker app which treats your goals like a Role Playing Game. - fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
🚨 CVE-2022-34011
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34013
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34012
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
🎖@cveNotify
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
🎖@cveNotify
Gitee
yadong.zhang/OneBlog
OneBlog,一个简洁美观、功能强大并且自适应的Java博客
🚨 CVE-2022-34170
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2021-41432
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
🎖@cveNotify
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
🎖@cveNotify
GitHub
Stored XSS in the Blog Content · Issue #88 · flatpressblog/flatpress
FlatPress 1.2.1 - Stored XSS in the Blog Content A stored Cross Site Scripting (XSS) vulnerability exists in version 1.2.1 of the FlatPress application that allows for arbitrary execution of JavaSc...
🚨 CVE-2022-34171
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-34172
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-34173
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2022-23078
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
🎖@cveNotify
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
🎖@cveNotify
GitHub
fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
A habit tracker app which treats your goals like a Role Playing Game. - fix(login): catch double-slash exploit · HabitRPG/habitica@5bcfdbe
🚨 CVE-2022-34174
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
🎖@cveNotify
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2017-20083
A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.
🎖@cveNotify
A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.
🎖@cveNotify
seclists.org
Full Disclosure: SEC Consult SA-20170207 :: Path Traversal, Backdoor accounts & KNX group address password bypass in JUNG Smart…
🚨 CVE-2022-23080
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
🎖@cveNotify
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
🎖@cveNotify
🚨 CVE-2022-34305
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
🎖@cveNotify
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
🎖@cveNotify
🚨 CVE-2021-26637
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
🎖@cveNotify
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
🎖@cveNotify
🚨 CVE-2022-34176
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
🎖@cveNotify
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
🎖@cveNotify
Jenkins Security Advisory 2022-06-22
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
🚨 CVE-2017-20084
A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.
🎖@cveNotify
A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.
🎖@cveNotify
Vuldb
CVE-2017-20084 | JUNG Smart Visu Server KNX Group Address backdoor
A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. This vulnerability is known as CVE-2017-20084. It is recommended to upgrade the affected component.