| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2175 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-21952 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2022 | A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java… | ||
| CVE-2021-40511 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2022 | OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service. | ||
| CVE-2021-40510 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2022 | XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs. | ||
| CVE-2022-34008 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder. | ||
| CVE-2022-33995 | Hig | 0.49 | 7.5 | 0.02 | Jun 21, 2022 | A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location. | ||
| CVE-2022-32973 | Hig | 0.57 | 8.8 | 0.01 | Jun 21, 2022 | An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges. | ||
| CVE-2022-2068 | Hig | 0.48 | 7.3 | 0.96 | Jun 21, 2022 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not… | ||
| CVE-2022-27872 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An… | ||
| CVE-2022-27871 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code. | ||
| CVE-2022-27870 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing TGA file. This vulnerability may be exploited to execute arbitrary code. | ||
| CVE-2022-27869 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code. | ||
| CVE-2022-27868 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2022-27867 | Hig | 0.51 | 7.8 | 0.01 | Jun 21, 2022 | A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2022-22979 | Hig | 0.49 | 7.5 | 0.01 | Jun 21, 2022 | In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework. | ||
| CVE-2022-1833 | Hig | 0.57 | 8.8 | 0.01 | Jun 21, 2022 | A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building… | ||
| CVE-2022-1665 | Hig | 0.53 | 8.2 | 0.00 | Jun 21, 2022 | A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot… | ||
| CVE-2022-33056 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php. | ||
| CVE-2022-33055 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php. | ||
| CVE-2022-33049 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user. | ||
| CVE-2022-33048 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php. | ||
| CVE-2017-20067 | Hig | 0.48 | 7.3 | 0.01 | Jun 21, 2022 | A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack… | ||
| CVE-2022-33913 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check. | ||
| CVE-2022-1720 | Hig | 0.00 | 7.8 | 0.02 | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||
| CVE-2021-41683 | Hig | 0.51 | 7.8 | 0.01 | Jun 20, 2022 | There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0 | ||
| CVE-2021-41682 | Hig | 0.51 | 7.8 | 0.01 | Jun 20, 2022 | There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.0 | ||
| CVE-2022-1939 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2022 | The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to | ||
| CVE-2022-1824 | Hig | 0.51 | 7.9 | 0.00 | Jun 20, 2022 | An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to… | ||
| CVE-2022-1823 | Hig | 0.51 | 7.9 | 0.00 | Jun 20, 2022 | Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and… | ||
| CVE-2022-1801 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for… | ||
| CVE-2022-1614 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions. | ||
| CVE-2022-1472 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2022 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection | ||
| CVE-2022-26669 | Hig | 0.57 | 8.8 | 0.01 | Jun 20, 2022 | ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data. | ||
| CVE-2022-26668 | Hig | 0.48 | 7.3 | 0.01 | Jun 20, 2022 | ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service. | ||
| CVE-2021-45918 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2022 | NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate… | ||
| CVE-2022-34006 | Hig | 0.51 | 7.8 | 0.00 | Jun 19, 2022 | An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands… | ||
| CVE-2022-2129 | Hig | 0.00 | 7.8 | 0.01 | Jun 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2126 | Hig | 0.00 | 7.8 | 0.01 | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2125 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2124 | Hig | 0.00 | 7.8 | 0.01 | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2014-125024 | Hig | 0.47 | 7.3 | 0.01 | Jun 19, 2022 | A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue. | ||
| CVE-2014-125020 | Hig | 0.47 | 7.3 | 0.01 | Jun 19, 2022 | A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_update_thread_context. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. | ||
| CVE-2014-125017 | Hig | 0.47 | 7.3 | 0.01 | Jun 18, 2022 | A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to… | ||
| CVE-2014-125015 | Hig | 0.47 | 7.3 | 0.01 | Jun 18, 2022 | A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. | ||
| CVE-2022-25856 | Hig | 0.42 | 7.5 | 0.02 | Jun 17, 2022 | The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link… | ||
| CVE-2022-25852 | — | Hig | 0.00 | 7.5 | 0.01 | Jun 17, 2022 | All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's… | |
| CVE-2022-25345 | Hig | 0.42 | 7.5 | 0.01 | Jun 17, 2022 | All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash. | ||
| CVE-2022-22138 | — | Hig | 0.49 | 7.5 | 0.01 | Jun 17, 2022 | All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation. | |
| CVE-2022-21213 | Hig | 0.42 | 7.5 | 0.02 | Jun 17, 2022 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target… | ||
| CVE-2022-31083 | Hig | 0.49 | 8.6 | 0.01 | Jun 17, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be… |
- risk 0.00cvss 7.8epss 0.01
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.49cvss 7.5epss 0.01
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java…
- risk 0.49cvss 7.5epss 0.01
OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
- risk 0.49cvss 7.5epss 0.01
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
- risk 0.51cvss 7.8epss 0.01
Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.
- risk 0.49cvss 7.5epss 0.02
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
- risk 0.57cvss 8.8epss 0.01
An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.
- risk 0.48cvss 7.3epss 0.96
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not…
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An…
- risk 0.51cvss 7.8epss 0.01
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing TGA file. This vulnerability may be exploited to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
- risk 0.49cvss 7.5epss 0.01
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
- risk 0.57cvss 8.8epss 0.01
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building…
- risk 0.53cvss 8.2epss 0.00
A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot…
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack…
- risk 0.49cvss 7.5epss 0.01
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
- risk 0.51cvss 7.8epss 0.01
There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0
- risk 0.51cvss 7.8epss 0.01
There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.0
- risk 0.47cvss 7.2epss 0.01
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
- risk 0.51cvss 7.9epss 0.00
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to…
- risk 0.51cvss 7.9epss 0.00
Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and…
- risk 0.49cvss 7.5epss 0.01
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for…
- risk 0.49cvss 7.5epss 0.01
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
- risk 0.47cvss 7.2epss 0.01
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
- risk 0.57cvss 8.8epss 0.01
ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.
- risk 0.48cvss 7.3epss 0.01
ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.
- risk 0.49cvss 7.5epss 0.01
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands…
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_update_thread_context. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to…
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
- risk 0.42cvss 7.5epss 0.02
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link…
- risk 0.00cvss 7.5epss 0.01
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's…
- risk 0.42cvss 7.5epss 0.01
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
- risk 0.49cvss 7.5epss 0.01
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
- risk 0.42cvss 7.5epss 0.02
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target…
- risk 0.49cvss 8.6epss 0.01
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be…