| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1534 | Hig | 0.00 | 7.1 | 0.00 | Apr 29, 2022 | Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a… | ||
| CVE-2022-1533 | Hig | 0.00 | 7.8 | 0.00 | Apr 29, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution. | ||
| CVE-2022-29555 | Hig | 0.57 | 8.8 | 0.00 | Apr 28, 2022 | The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. | ||
| CVE-2022-28060 | Hig | 0.49 | 7.5 | 0.02 | Apr 28, 2022 | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | ||
| CVE-2022-29411 | Hig | 0.54 | 8.3 | 0.01 | Apr 28, 2022 | SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id). | ||
| CVE-2022-29410 | Hig | 0.48 | 7.4 | 0.01 | Apr 28, 2022 | Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids). | ||
| CVE-2022-29585 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of). | ||
| CVE-2022-28892 | Hig | 0.57 | 8.8 | 0.00 | Apr 28, 2022 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable. | ||
| CVE-2022-24879 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is… | ||
| CVE-2022-22782 | Hig | 0.51 | 7.9 | 0.00 | Apr 28, 2022 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was… | ||
| CVE-2022-22781 | Hig | 0.49 | 7.5 | 0.00 | Apr 28, 2022 | The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure… | ||
| CVE-2021-43939 | Hig | 0.57 | 8.8 | 0.01 | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints. | ||
| CVE-2022-24935 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | Lexmark products through 2022-02-10 have Incorrect Access Control. | ||
| CVE-2021-33436 | Hig | 0.47 | 7.3 | 0.00 | Apr 28, 2022 | NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and… | ||
| CVE-2021-3523 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address. | ||
| CVE-2022-28194 | Hig | 0.47 | 7.3 | 0.00 | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service,… | ||
| CVE-2022-22315 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2022 | IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955. | ||
| CVE-2022-22278 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack | ||
| CVE-2022-22275 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable. | ||
| CVE-2022-22521 | Hig | 0.47 | 7.3 | 0.01 | Apr 27, 2022 | In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin. | ||
| CVE-2021-38919 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021 | ||
| CVE-2021-38878 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756. | ||
| CVE-2021-34602 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges. | ||
| CVE-2021-34592 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields. | ||
| CVE-2021-34591 | Hig | 0.51 | 7.8 | 0.00 | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd. | ||
| CVE-2021-34589 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface. | ||
| CVE-2021-34588 | Hig | 0.56 | 8.6 | 0.01 | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot . | ||
| CVE-2022-29505 | Hig | 0.51 | 7.8 | 0.00 | Apr 27, 2022 | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation. | ||
| CVE-2022-27905 | Hig | 0.47 | 7.2 | 0.01 | Apr 27, 2022 | In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this. | ||
| CVE-2022-27239 | Hig | 0.00 | 7.8 | 0.01 | Apr 27, 2022 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | ||
| CVE-2021-46441 | Hig | 0.60 | 8.8 | 0.33 | Apr 27, 2022 | In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization. | ||
| CVE-2021-46421 | Hig | 0.49 | 7.5 | 0.06 | Apr 27, 2022 | Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. | ||
| CVE-2021-46420 | Hig | 0.49 | 7.5 | 0.06 | Apr 27, 2022 | Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. | ||
| CVE-2022-29701 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | ||
| CVE-2022-29700 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification. | ||
| CVE-2022-28085 | Hig | 0.00 | 7.8 | 0.01 | Apr 27, 2022 | A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). | ||
| CVE-2022-28918 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=. | ||
| CVE-2022-28528 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | ||
| CVE-2022-28527 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del. | ||
| CVE-2022-28525 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | ||
| CVE-2022-28523 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | ||
| CVE-2022-28059 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. | ||
| CVE-2022-28058 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php. | ||
| CVE-2021-26629 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’. | ||
| CVE-2021-26628 | — | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2022 | Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as… | |
| CVE-2022-24883 | Hig | 0.00 | 7.4 | 0.02 | Apr 26, 2022 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not… | ||
| CVE-2022-24881 | Hig | 0.50 | 8.8 | 0.03 | Apr 26, 2022 | Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates… | ||
| CVE-2022-23942 | — | Hig | 0.49 | 7.5 | 0.03 | Apr 26, 2022 | Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure. | |
| CVE-2022-23457 | — | Hig | 0.42 | 7.5 | 0.03 | Apr 25, 2022 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a… | |
| CVE-2021-35250 | Hig | 0.50 | 7.5 | 0.13 | Apr 25, 2022 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1. |
- risk 0.00cvss 7.1epss 0.00
Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a…
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.
- risk 0.57cvss 8.8epss 0.00
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
- risk 0.49cvss 7.5epss 0.02
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
- risk 0.54cvss 8.3epss 0.01
SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).
- risk 0.48cvss 7.4epss 0.01
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
- risk 0.49cvss 7.5epss 0.01
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
- risk 0.57cvss 8.8epss 0.00
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
- risk 0.49cvss 7.5epss 0.01
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is…
- risk 0.51cvss 7.9epss 0.00
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was…
- risk 0.49cvss 7.5epss 0.00
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure…
- risk 0.57cvss 8.8epss 0.01
Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints.
- risk 0.49cvss 7.5epss 0.01
Lexmark products through 2022-02-10 have Incorrect Access Control.
- risk 0.47cvss 7.3epss 0.00
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and…
- risk 0.49cvss 7.5epss 0.01
A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.
- risk 0.47cvss 7.3epss 0.00
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service,…
- risk 0.57cvss 8.8epss 0.01
IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.
- risk 0.49cvss 7.5epss 0.01
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
- risk 0.49cvss 7.5epss 0.01
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
- risk 0.47cvss 7.3epss 0.01
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.
- risk 0.49cvss 7.5epss 0.01
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021
- risk 0.49cvss 7.5epss 0.01
IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
- risk 0.57cvss 8.8epss 0.01
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.
- risk 0.57cvss 8.8epss 0.01
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.
- risk 0.51cvss 7.8epss 0.00
In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.
- risk 0.49cvss 7.5epss 0.01
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.
- risk 0.56cvss 8.6epss 0.01
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
- risk 0.51cvss 7.8epss 0.00
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
- risk 0.47cvss 7.2epss 0.01
In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.
- risk 0.00cvss 7.8epss 0.01
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
- risk 0.60cvss 8.8epss 0.33
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.
- risk 0.49cvss 7.5epss 0.06
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.06
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
- risk 0.49cvss 7.5epss 0.01
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
- risk 0.00cvss 7.8epss 0.01
A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).
- risk 0.53cvss 8.1epss 0.01
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.
- risk 0.57cvss 8.8epss 0.01
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
- risk 0.53cvss 8.1epss 0.01
dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.
- risk 0.57cvss 8.8epss 0.01
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.
- risk 0.53cvss 8.1epss 0.01
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
- risk 0.53cvss 8.1epss 0.01
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
- risk 0.53cvss 8.1epss 0.01
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
- risk 0.57cvss 8.8epss 0.01
A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.
- risk 0.53cvss 8.1epss 0.01
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as…
- risk 0.00cvss 7.4epss 0.02
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not…
- risk 0.50cvss 8.8epss 0.03
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates…
- risk 0.49cvss 7.5epss 0.03
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
- risk 0.42cvss 7.5epss 0.03
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a…
- risk 0.50cvss 7.5epss 0.13
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.