| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1748 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2022 | Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability. | ||
| CVE-2022-1373 | Hig | 0.51 | 7.2 | 0.11 | Aug 17, 2022 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"… | ||
| CVE-2022-1069 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2022 | A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | ||
| CVE-2021-26639 | Hig | 0.53 | 8.1 | 0.00 | Aug 17, 2022 | This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. | ||
| CVE-2022-36216 | Hig | 0.47 | 7.2 | 0.02 | Aug 17, 2022 | DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. | ||
| CVE-2022-36215 | Hig | 0.47 | 7.2 | 0.02 | Aug 17, 2022 | DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php. | ||
| CVE-2022-2862 | Hig | 0.00 | 7.8 | 0.01 | Aug 17, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0221. | ||
| CVE-2022-2849 | Hig | 0.00 | 7.8 | 0.00 | Aug 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. | ||
| CVE-2022-38149 | Hig | 0.42 | 7.5 | 0.01 | Aug 17, 2022 | HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2. | ||
| CVE-2022-36186 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2022 | A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1. | ||
| CVE-2022-31262 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2022 | An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in… | ||
| CVE-2022-30262 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2022 | The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images… | ||
| CVE-2022-2845 | Hig | 0.00 | 7.8 | 0.01 | Aug 17, 2022 | Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218. | ||
| CVE-2022-37459 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2022 | Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue. | ||
| CVE-2021-45454 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2022 | Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon. | ||
| CVE-2022-1410 | Hig | 0.52 | 8.0 | 0.01 | Aug 17, 2022 | OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions. | ||
| CVE-2022-1400 | Hig | 0.46 | 7.1 | 0.01 | Aug 17, 2022 | Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00. | ||
| CVE-2021-42052 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter. | ||
| CVE-2022-38238 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc. | ||
| CVE-2022-38237 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc. | ||
| CVE-2022-38236 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc. | ||
| CVE-2022-38231 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc. | ||
| CVE-2022-38229 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc. | ||
| CVE-2022-38228 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. | ||
| CVE-2022-38227 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp. | ||
| CVE-2022-37781 | — | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.inc. | |
| CVE-2022-37437 | Hig | 0.48 | 7.4 | 0.00 | Aug 16, 2022 | When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and… | ||
| CVE-2022-36144 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via base64_encode. | ||
| CVE-2022-36143 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via __interceptor_strlen.part at /sanitizer_common/sanitizer_common_interceptors.inc. | ||
| CVE-2022-36142 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Reader::getU30(). | ||
| CVE-2022-36139 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Writer::writeByte(unsigned char). | ||
| CVE-2022-35011 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2022 | PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c. | ||
| CVE-2022-35003 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a global buffer overflow via ucDitherBuffer at /src/jpeg.inl. | ||
| CVE-2022-34998 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl. | ||
| CVE-2022-34256 | Hig | 0.42 | 7.5 | 0.02 | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data.… | ||
| CVE-2022-34255 | Hig | 0.50 | 8.8 | 0.02 | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to… | ||
| CVE-2022-34254 | Hig | 0.50 | 8.8 | 0.02 | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could be abused by an attacker to inject malicious scripts into the… | ||
| CVE-2022-34253 | Hig | 0.40 | 7.2 | 0.04 | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.… | ||
| CVE-2022-2833 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | Endless Infinite loop in Blender-thumnailing due to logical bugs. | ||
| CVE-2022-2832 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity. | ||
| CVE-2022-2831 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption. | ||
| CVE-2020-1756 | Hig | 0.47 | 7.2 | 0.01 | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. | ||
| CVE-2020-14322 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service. | ||
| CVE-2020-14321 | Hig | 0.55 | 8.8 | 0.17 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | ||
| CVE-2020-10728 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from… | ||
| CVE-2022-37393 | Hig | 0.47 | 7.8 | 0.02 | Aug 16, 2022 | Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as… | ||
| CVE-2022-38184 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs. | ||
| CVE-2022-30576 | Hig | 0.57 | 8.7 | 0.00 | Aug 16, 2022 | The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute… | ||
| CVE-2022-30575 | Hig | 0.47 | 7.3 | 0.01 | Aug 16, 2022 | The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged… | ||
| CVE-2022-38362 | Hig | 0.57 | 8.8 | 0.02 | Aug 16, 2022 | Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. |
- risk 0.49cvss 7.5epss 0.01
Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.
- risk 0.51cvss 7.2epss 0.11
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"…
- risk 0.49cvss 7.5epss 0.01
A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
- risk 0.53cvss 8.1epss 0.00
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
- risk 0.47cvss 7.2epss 0.02
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
- risk 0.47cvss 7.2epss 0.02
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0221.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
- risk 0.42cvss 7.5epss 0.01
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
- risk 0.49cvss 7.5epss 0.01
A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.
- risk 0.51cvss 7.8epss 0.00
An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in…
- risk 0.51cvss 7.8epss 0.00
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images…
- risk 0.00cvss 7.8epss 0.01
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
- risk 0.51cvss 7.8epss 0.00
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
- risk 0.49cvss 7.5epss 0.01
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon.
- risk 0.52cvss 8.0epss 0.01
OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.
- risk 0.46cvss 7.1epss 0.01
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.
- risk 0.49cvss 7.5epss 0.01
IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.
- risk 0.51cvss 7.8epss 0.00
fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.inc.
- risk 0.48cvss 7.4epss 0.00
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and…
- risk 0.51cvss 7.8epss 0.00
SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via base64_encode.
- risk 0.51cvss 7.8epss 0.00
SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via __interceptor_strlen.part at /sanitizer_common/sanitizer_common_interceptors.inc.
- risk 0.51cvss 7.8epss 0.00
SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Reader::getU30().
- risk 0.51cvss 7.8epss 0.00
SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Writer::writeByte(unsigned char).
- risk 0.57cvss 8.8epss 0.01
PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c.
- risk 0.51cvss 7.8epss 0.00
JPEGDEC commit be4843c was discovered to contain a global buffer overflow via ucDitherBuffer at /src/jpeg.inl.
- risk 0.51cvss 7.8epss 0.00
JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl.
- risk 0.42cvss 7.5epss 0.02
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data.…
- risk 0.50cvss 8.8epss 0.02
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to…
- risk 0.50cvss 8.8epss 0.02
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could be abused by an attacker to inject malicious scripts into the…
- risk 0.40cvss 7.2epss 0.04
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.…
- risk 0.49cvss 7.5epss 0.01
Endless Infinite loop in Blender-thumnailing due to logical bugs.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.
- risk 0.47cvss 7.2epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
- risk 0.49cvss 7.5epss 0.01
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
- risk 0.55cvss 8.8epss 0.17
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
- risk 0.51cvss 7.8epss 0.00
A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from…
- risk 0.47cvss 7.8epss 0.02
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as…
- risk 0.49cvss 7.5epss 0.01
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
- risk 0.57cvss 8.7epss 0.00
The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute…
- risk 0.47cvss 7.3epss 0.01
The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged…
- risk 0.57cvss 8.8epss 0.02
Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.