| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43666 | Hig | 0.49 | 7.5 | 0.02 | Mar 24, 2022 | A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. | ||
| CVE-2022-25568 | — | Hig | 0.42 | 7.5 | 0.07 | Mar 24, 2022 | MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured. | |
| CVE-2022-0153 | Hig | 0.42 | 7.5 | 0.01 | Mar 24, 2022 | SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1. | ||
| CVE-2022-0551 | Hig | 0.47 | 7.2 | 0.01 | Mar 24, 2022 | Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi… | ||
| CVE-2022-0550 | Hig | 0.47 | 7.2 | 0.01 | Mar 24, 2022 | Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects:… | ||
| CVE-2022-1061 | Hig | 0.00 | 7.5 | 0.01 | Mar 24, 2022 | Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. | ||
| CVE-2022-0315 | Hig | 0.42 | 7.5 | 0.01 | Mar 24, 2022 | Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. | ||
| CVE-2022-25268 | Hig | 0.57 | 8.8 | 0.00 | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. | ||
| CVE-2022-25267 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files). | ||
| CVE-2022-27192 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files. | ||
| CVE-2022-22819 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code… | ||
| CVE-2021-44226 | Hig | 0.48 | 7.3 | 0.01 | Mar 23, 2022 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse… | ||
| CVE-2022-24757 | Hig | 0.42 | 7.5 | 0.01 | Mar 23, 2022 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other… | ||
| CVE-2022-24730 | Hig | 0.50 | 7.7 | 0.01 | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with… | ||
| CVE-2021-28278 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c. | ||
| CVE-2021-28277 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c. | ||
| CVE-2021-28276 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c. | ||
| CVE-2022-24291 | Hig | 0.49 | 7.5 | 0.04 | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | ||
| CVE-2022-1030 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2022 | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has… | ||
| CVE-2022-0981 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2022 | A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended. | ||
| CVE-2022-0889 | Hig | 0.47 | 7.2 | 0.01 | Mar 23, 2022 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add… | ||
| CVE-2022-0834 | Hig | 0.47 | 7.2 | 0.01 | Mar 23, 2022 | The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts… | ||
| CVE-2021-4197 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for… | ||
| CVE-2021-4156 | Hig | 0.00 | 7.1 | 0.02 | Mar 23, 2022 | An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds… | ||
| CVE-2021-3748 | Hig | 0.00 | 7.5 | 0.01 | Mar 23, 2022 | A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to… | ||
| CVE-2021-3618 | Hig | 0.48 | 7.4 | 0.02 | Mar 23, 2022 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can… | ||
| CVE-2021-3589 | Hig | 0.45 | 8.0 | 0.01 | Mar 23, 2022 | An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system… | ||
| CVE-2021-27475 | Hig | 0.56 | 8.6 | 0.03 | Mar 23, 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in… | ||
| CVE-2021-27471 | Hig | 0.50 | 7.7 | 0.03 | Mar 23, 2022 | The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file… | ||
| CVE-2021-27430 | Hig | 0.55 | 8.4 | 0.00 | Mar 23, 2022 | GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR. | ||
| CVE-2021-27422 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication. | ||
| CVE-2022-26243 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function. | ||
| CVE-2021-38772 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function. | ||
| CVE-2021-46064 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image. | ||
| CVE-2021-44139 | Hig | 0.49 | 7.5 | 0.06 | Mar 23, 2022 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). | ||
| CVE-2021-43738 | Hig | 0.57 | 8.8 | 0.00 | Mar 23, 2022 | An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account. | ||
| CVE-2021-44759 | Hig | 0.53 | 8.1 | 0.02 | Mar 23, 2022 | Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0. | ||
| CVE-2021-44040 | Hig | 0.49 | 7.5 | 0.02 | Mar 23, 2022 | Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1. | ||
| CVE-2022-0635 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. | ||
| CVE-2021-45757 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2022 | ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS). | ||
| CVE-2022-1033 | Hig | 0.00 | 7.8 | 0.01 | Mar 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2022-27666 | Hig | 0.00 | 7.8 | 0.06 | Mar 23, 2022 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. | ||
| CVE-2022-1031 | Hig | 0.00 | 7.8 | 0.01 | Mar 22, 2022 | Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6. | ||
| CVE-2022-24774 | Hig | 0.00 | 7.1 | 0.01 | Mar 22, 2022 | CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit… | ||
| CVE-2022-24764 | Hig | 0.00 | 7.5 | 0.02 | Mar 22, 2022 | PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not… | ||
| CVE-2022-1036 | Hig | 0.42 | 7.5 | 0.01 | Mar 22, 2022 | Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12. | ||
| CVE-2022-0667 | Hig | 0.49 | 7.5 | 0.01 | Mar 22, 2022 | When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 | ||
| CVE-2021-45810 | Hig | 0.49 | 7.5 | 0.01 | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect… | ||
| CVE-2022-1034 | — | Hig | 0.40 | 7.2 | 0.01 | Mar 22, 2022 | There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. | |
| CVE-2022-0386 | Hig | 0.57 | 8.8 | 0.01 | Mar 22, 2022 | A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. |
- risk 0.49cvss 7.5epss 0.02
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
- risk 0.42cvss 7.5epss 0.07
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
- risk 0.42cvss 7.5epss 0.01
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.
- risk 0.47cvss 7.2epss 0.01
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi…
- risk 0.47cvss 7.2epss 0.01
Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects:…
- risk 0.00cvss 7.5epss 0.01
Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.
- risk 0.42cvss 7.5epss 0.01
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
- risk 0.57cvss 8.8epss 0.00
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
- risk 0.57cvss 8.8epss 0.01
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).
- risk 0.49cvss 7.5epss 0.01
The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.
- risk 0.51cvss 7.8epss 0.01
NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code…
- risk 0.48cvss 7.3epss 0.01
Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse…
- risk 0.42cvss 7.5epss 0.01
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other…
- risk 0.50cvss 7.7epss 0.01
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with…
- risk 0.51cvss 7.8epss 0.01
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
- risk 0.51cvss 7.8epss 0.01
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
- risk 0.49cvss 7.5epss 0.01
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
- risk 0.49cvss 7.5epss 0.04
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.
- risk 0.57cvss 8.8epss 0.01
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has…
- risk 0.57cvss 8.8epss 0.01
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.
- risk 0.47cvss 7.2epss 0.01
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add…
- risk 0.47cvss 7.2epss 0.01
The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts…
- risk 0.51cvss 7.8epss 0.01
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for…
- risk 0.00cvss 7.1epss 0.02
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds…
- risk 0.00cvss 7.5epss 0.01
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to…
- risk 0.48cvss 7.4epss 0.02
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can…
- risk 0.45cvss 8.0epss 0.01
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…
- risk 0.56cvss 8.6epss 0.03
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in…
- risk 0.50cvss 7.7epss 0.03
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file…
- risk 0.55cvss 8.4epss 0.00
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
- risk 0.49cvss 7.5epss 0.01
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
- risk 0.49cvss 7.5epss 0.01
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.
- risk 0.49cvss 7.5epss 0.01
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- risk 0.51cvss 7.8epss 0.01
IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.
- risk 0.49cvss 7.5epss 0.06
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
- risk 0.53cvss 8.1epss 0.02
Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.
- risk 0.49cvss 7.5epss 0.02
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.
- risk 0.49cvss 7.5epss 0.01
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
- risk 0.49cvss 7.5epss 0.01
ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).
- risk 0.00cvss 7.8epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 7.8epss 0.06
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
- risk 0.00cvss 7.8epss 0.01
Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.
- risk 0.00cvss 7.1epss 0.01
CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…
- risk 0.00cvss 7.5epss 0.02
PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not…
- risk 0.42cvss 7.5epss 0.01
Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.
- risk 0.49cvss 7.5epss 0.01
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
- risk 0.49cvss 7.5epss 0.01
GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect…
- risk 0.40cvss 7.2epss 0.01
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.
- risk 0.57cvss 8.8epss 0.01
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.