π¨ CVE-2020-10735
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
π@cveNotify
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
π@cveNotify
π¨ CVE-2022-38351
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
π@cveNotify
A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.
π@cveNotify
π¨ CVE-2022-37246
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
π@cveNotify
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
π@cveNotify
GitHub
Fixed an XSS vulnerability Β· craftcms/cms@1d5fdba
Build bespoke content experiences with Craft. Contribute to craftcms/cms development by creating an account on GitHub.
π¨ CVE-2019-5641
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
π@cveNotify
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
π@cveNotify
π¨ CVE-2022-3214
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Version 1.8.0 and prior have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.
π@cveNotify
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Version 1.8.0 and prior have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.
π@cveNotify
π¨ CVE-2022-40068
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.
π@cveNotify
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.
π@cveNotify
GitHub
Vuln/Tenda AC21/10 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40067
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetVirtualSer.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetVirtualSer.
π@cveNotify
GitHub
Vuln/Tenda AC21/9 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40070
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg.
π@cveNotify
GitHub
Vuln/Tenda AC21/8 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40069
]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime.
π@cveNotify
]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime.
π@cveNotify
GitHub
Vuln/Tenda AC21/6 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2020-25491
6Kare Emakin 5.0.341.0 is affected by Cross Site Scripting (XSS) via the /rpc/membership/setProfile DisplayName field, which is mishandled when rendering the Activity Stream page.
π@cveNotify
6Kare Emakin 5.0.341.0 is affected by Cross Site Scripting (XSS) via the /rpc/membership/setProfile DisplayName field, which is mishandled when rendering the Activity Stream page.
π@cveNotify
Gist
CVE-2020-25491
CVE-2020-25491. GitHub Gist: instantly share code, notes, and snippets.
π¨ CVE-2022-40073
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.
π@cveNotify
GitHub
Vuln/Tenda AC21/5 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40072
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement.
π@cveNotify
GitHub
Vuln/Tenda AC21/7 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40071
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName.
π@cveNotify
GitHub
Vuln/Tenda AC21/2 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40075
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.
π@cveNotify
GitHub
Vuln/Tenda AC21/1 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40074
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi.
π@cveNotify
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi.
π@cveNotify
GitHub
Vuln/Tenda AC21/3 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-37258
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
π@cveNotify
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
π@cveNotify
GitHub
steal/ext/npm-convert.js at c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9 Β· stealjs/steal
Gets JavaScript. Contribute to stealjs/steal development by creating an account on GitHub.
π¨ CVE-2022-40076
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.
π@cveNotify
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.
π@cveNotify
GitHub
Vuln/Tenda AC21/4 at main Β· xxy1126/Vuln
Contribute to xxy1126/Vuln development by creating an account on GitHub.
π¨ CVE-2022-40424
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0
π@cveNotify
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0
π@cveNotify
PyPI
democritus-networking
Democritus functions for working with network requests.
π1
π¨ CVE-2022-38885
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
π@cveNotify
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
π@cveNotify
PyPI
d8s-netstrings
Democritus functions for working with Netstrings.
π1
π¨ CVE-2022-23766
An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.
π@cveNotify
An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.
π@cveNotify
www.krcert.or.kr
KISA μΈν°λ· 보νΈλλΌ&KrCERT
π¨ CVE-2022-38881
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
π@cveNotify
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
π@cveNotify
PyPI
d8s-archives
Democritus functions for working with archives.