| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4291 | Hig | 0.50 | 7.7 | 0.00 | Dec 8, 2022 | The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the… | ||
| CVE-2022-3092 | Hig | 0.51 | 7.8 | 0.00 | Dec 8, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code. | ||
| CVE-2022-3084 | Hig | 0.51 | 7.8 | 0.00 | Dec 8, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code. | ||
| CVE-2022-2952 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code. | ||
| CVE-2022-2948 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code. | ||
| CVE-2022-2002 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code. | ||
| CVE-2022-23487 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can… | ||
| CVE-2022-23486 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of… | ||
| CVE-2022-46770 | Hig | 0.53 | 7.5 | 0.21 | Dec 7, 2022 | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255). | ||
| CVE-2022-44373 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2022 | A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution. | ||
| CVE-2022-43581 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805. | ||
| CVE-2022-44393 | Hig | 0.47 | 7.2 | 0.01 | Dec 7, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=. | ||
| CVE-2022-41720 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example,… | ||
| CVE-2022-40966 | Hig | 0.57 | 8.8 | 0.00 | Dec 7, 2022 | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and… | ||
| CVE-2022-46741 | Hig | 0.39 | 7.1 | 0.01 | Dec 7, 2022 | Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. | ||
| CVE-2022-44620 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2022 | Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | ||
| CVE-2022-44608 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition. | ||
| CVE-2022-44606 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2022 | OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | ||
| CVE-2022-43667 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | ||
| CVE-2022-43660 | Hig | 0.47 | 7.2 | 0.01 | Dec 7, 2022 | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are… | ||
| CVE-2022-43509 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | ||
| CVE-2022-43508 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2022 | Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | ||
| CVE-2022-43468 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2022 | External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article… | ||
| CVE-2022-43464 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2022 | Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | ||
| CVE-2022-41800 | Hig | 0.65 | 8.7 | 0.62 | Dec 7, 2022 | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security… | ||
| CVE-2022-41622 | Hig | 0.67 | 8.8 | 0.88 | Dec 7, 2022 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||
| CVE-2022-44849 | Hig | 0.57 | 8.8 | 0.00 | Dec 7, 2022 | A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account. | ||
| CVE-2022-45009 | Hig | 0.47 | 7.2 | 0.01 | Dec 7, 2022 | Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-44942 | Hig | 0.46 | 8.1 | 0.01 | Dec 7, 2022 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. | ||
| CVE-2022-45915 | Hig | 0.58 | 8.8 | 0.05 | Dec 7, 2022 | ILIAS before 7.16 allows OS Command Injection. | ||
| CVE-2022-44030 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user. | ||
| CVE-2022-45829 | Hig | 0.57 | 8.7 | 0.01 | Dec 6, 2022 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. | ||
| CVE-2022-41902 | Hig | 0.39 | 7.1 | 0.00 | Dec 6, 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is… | ||
| CVE-2022-46333 | Hig | 0.47 | 7.2 | 0.01 | Dec 6, 2022 | The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below. | ||
| CVE-2022-23475 | Hig | 0.00 | 8.8 | 0.00 | Dec 6, 2022 | daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped… | ||
| CVE-2022-4147 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no… | ||
| CVE-2022-46154 | Hig | 0.00 | 8.6 | 0.01 | Dec 6, 2022 | Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed… | ||
| CVE-2022-45548 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2022 | AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. | ||
| CVE-2022-43867 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437. | ||
| CVE-2022-23470 | Hig | 0.00 | 8.6 | 0.01 | Dec 6, 2022 | Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects… | ||
| CVE-2022-35843 | Hig | 0.53 | 8.1 | 0.01 | Dec 6, 2022 | An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0… | ||
| CVE-2022-46382 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2022 | RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. After signing into Digital Rebar, users are issued authentication tokens tied to their account to perform actions within Digital… | ||
| CVE-2022-44289 | Hig | 0.57 | 8.8 | 0.03 | Dec 6, 2022 | Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell. | ||
| CVE-2022-41325 | Hig | 0.51 | 7.8 | 0.01 | Dec 6, 2022 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions. | ||
| CVE-2022-38123 | Hig | 0.57 | 8.7 | 0.01 | Dec 6, 2022 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0. | ||
| CVE-2022-42778 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed. | ||
| CVE-2022-42777 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-42776 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed. | ||
| CVE-2022-39102 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39101 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
- risk 0.50cvss 7.7epss 0.00
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the…
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
- risk 0.49cvss 7.5epss 0.01
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can…
- risk 0.49cvss 7.5epss 0.01
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of…
- risk 0.53cvss 7.5epss 0.21
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).
- risk 0.57cvss 8.8epss 0.01
A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution.
- risk 0.49cvss 7.5epss 0.01
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.
- risk 0.49cvss 7.5epss 0.01
On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example,…
- risk 0.57cvss 8.8epss 0.00
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and…
- risk 0.39cvss 7.1epss 0.01
Out-of-bounds read in gather_tree in PaddlePaddle before 2.4.
- risk 0.57cvss 8.8epss 0.01
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition.
- risk 0.57cvss 8.8epss 0.01
OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
- risk 0.47cvss 7.2epss 0.01
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are…
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
- risk 0.51cvss 7.8epss 0.00
Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
- risk 0.49cvss 7.5epss 0.01
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article…
- risk 0.57cvss 8.8epss 0.01
Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- risk 0.65cvss 8.7epss 0.62
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security…
- risk 0.67cvss 8.8epss 0.88
In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
- risk 0.47cvss 7.2epss 0.01
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.46cvss 8.1epss 0.01
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
- risk 0.58cvss 8.8epss 0.05
ILIAS before 7.16 allows OS Command Injection.
- risk 0.49cvss 7.5epss 0.01
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
- risk 0.57cvss 8.7epss 0.01
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
- risk 0.39cvss 7.1epss 0.00
TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that determine the sizes of inputs and outputs. If the inputs given are greater than or equal to the sizes of the outputs, an out-of-bounds memory read or a crash is…
- risk 0.47cvss 7.2epss 0.01
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below.
- risk 0.00cvss 8.8epss 0.00
daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped…
- risk 0.49cvss 7.5epss 0.01
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no…
- risk 0.00cvss 8.6epss 0.01
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed…
- risk 0.57cvss 8.8epss 0.01
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
- risk 0.51cvss 7.8epss 0.00
IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container. IBM X-Force ID: 239437.
- risk 0.00cvss 8.6epss 0.01
Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects…
- risk 0.53cvss 8.1epss 0.01
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 through 2.0.10, 1.2.0…
- risk 0.57cvss 8.8epss 0.01
RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. After signing into Digital Rebar, users are issued authentication tokens tied to their account to perform actions within Digital…
- risk 0.57cvss 8.8epss 0.03
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
- risk 0.51cvss 7.8epss 0.01
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
- risk 0.57cvss 8.7epss 0.01
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
- risk 0.51cvss 7.8epss 0.00
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.