๐จ CVE-2020-4269
IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.
๐@cveNotify
IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.
๐@cveNotify
Ibmcloud
IBM X-Force Exchange
IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
๐จ CVE-2020-4274
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.
๐@cveNotify
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.
๐@cveNotify
๐จ CVE-2020-4294
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.
๐@cveNotify
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.
๐@cveNotify
๐จ CVE-2022-33061
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
๐@cveNotify
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
๐@cveNotify
GitHub
bug_report/vendors/oretnom23/online-railway-reservation-system/SQLi-9.md at main ยท debug601/bug_report
Contribute to debug601/bug_report development by creating an account on GitHub.
๐จ CVE-2022-33060
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
๐@cveNotify
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
๐@cveNotify
GitHub
bug_report/vendors/oretnom23/online-railway-reservation-system/SQLi-8.md at main ยท debug601/bug_report
Contribute to debug601/bug_report development by creating an account on GitHub.
๐จ CVE-2022-32399
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32397
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32398
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32394
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32396
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4
๐@cveNotify
GitHub
BugBounty/cve-2022-32396.md at main ยท Dyrandy/BugBounty
Prison Management System Bugs. Contribute to Dyrandy/BugBounty development by creating an account on GitHub.
๐จ CVE-2022-32395
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32392
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-32391
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4
๐@cveNotify
GitHub
BugBounty/cve-2022-32391.md at main ยท Dyrandy/BugBounty
Prison Management System Bugs. Contribute to Dyrandy/BugBounty development by creating an account on GitHub.
๐จ CVE-2022-32393
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4
๐@cveNotify
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4
๐@cveNotify
SourceCodester
Prison Management System in PHP/OOP Free Source Code
Introduction This project is entitled Prison Management System. This is a web-based application project developed in PHP and MySQL Database. The main purpose of this project is to provide an online and automated platform for the Prison to manage the inmates'โฆ
๐จ CVE-2022-31009
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
๐@cveNotify
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.
๐@cveNotify
GitHub
chore: remove unnecessary assert SQCORE-1299 (#5660) ยท wireapp/wire-ios@caa0e27
* chore: remove unnecessary assert
* empty
* empty
๐จ CVE-2017-20088
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
๐@cveNotify
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
๐@cveNotify
Vuldb
CVE-2017-20088 | Atahualpa Theme cross-site request forgery
A vulnerability classified as problematic has been found in Atahualpa Theme. This vulnerability is traded as CVE-2017-20088.
๐จ CVE-2022-2182
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
๐@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
๐@cveNotify
GitHub
patch 8.2.5150: read past the end of the first line with ":0;'{" ยท vim/vim@f7c7c3f
Problem: Read past the end of the first line with ":0;'{".
Solution: When on line zero check the column is valid for line one.
Solution: When on line zero check the column is valid for line one.
๐จ CVE-2022-34299
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
๐@cveNotify
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
๐@cveNotify
GitHub
heap overflow in dwarf_global_formref_b ยท Issue #119 ยท davea42/libdwarf-code
asan output: ================================================================= ==3946410==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61b000000697 at pc 0x0000005d9f2d bp 0x7fffffff9...
๐จ CVE-2022-34328
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
๐@cveNotify
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
๐@cveNotify
GitHub
GitHub - jenaye/PMB
Contribute to jenaye/PMB development by creating an account on GitHub.
๐จ CVE-2022-34300
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
๐@cveNotify
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
๐@cveNotify
GitHub
heap overflow in tinyexr::DecodePixelData ยท Issue #167 ยท syoyo/tinyexr
desc There is a heap based buffer overflow in tinyexr::DecodePixelData before 20220506 that could cause remote code execution depending on the usage of this program. asan output ==2363537==ERROR: A...