| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23451 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2023 | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial… | ||
| CVE-2021-33970 | Cri | 0.65 | 10.0 | 0.03 | Apr 19, 2023 | Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges. | ||
| CVE-2021-33975 | Cri | 0.65 | 10.0 | 0.01 | Apr 19, 2023 | Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges. | ||
| CVE-2021-33972 | Cri | 0.65 | 10.0 | 0.01 | Apr 19, 2023 | Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges. | ||
| CVE-2023-21096 | Cri | 0.64 | 9.8 | 0.00 | Apr 19, 2023 | In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L… | ||
| CVE-2023-2136 | Cri | 0.75 | 9.6 | 0.06 | KEV | Apr 19, 2023 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2023-29527 | Cri | 0.64 | 9.9 | 0.01 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groovy script content. Viewing… | ||
| CVE-2023-29526 | Cri | 0.64 | 9.9 | 0.01 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either… | ||
| CVE-2023-29525 | Cri | 0.64 | 9.9 | 0.78 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint.… | ||
| CVE-2023-29524 | Cri | 0.70 | 9.9 | 0.76 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your user profile with the object… | ||
| CVE-2023-29523 | Cri | 0.58 | 9.9 | 0.02 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted… | ||
| CVE-2023-29522 | Cri | 0.57 | 9.9 | 0.02 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access… | ||
| CVE-2023-29519 | Cri | 0.52 | 9.0 | 0.02 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a… | ||
| CVE-2023-29518 | Cri | 0.57 | 9.9 | 0.01 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping… | ||
| CVE-2023-29516 | Cri | 0.63 | 9.9 | 0.66 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The… | ||
| CVE-2023-29514 | Cri | 0.57 | 9.9 | 0.02 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on any document (e.g., their own user profile) can execute code with programming rights, leading to remote code execution. This vulnerability has… | ||
| CVE-2023-29512 | Cri | 0.57 | 9.9 | 0.01 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki… | ||
| CVE-2023-29510 | Cri | 0.57 | 9.9 | 0.02 | Apr 19, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such translations are often included… | ||
| CVE-2021-28254 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2023 | A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands. | ||
| CVE-2023-28004 | Cri | 0.64 | 9.8 | 0.01 | Apr 18, 2023 | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution. | ||
| CVE-2023-29412 | Cri | 0.64 | 9.8 | 0.01 | Apr 18, 2023 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface. | ||
| CVE-2023-29411 | Cri | 0.64 | 9.8 | 0.01 | Apr 18, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. | ||
| CVE-2023-28839 | Cri | 0.00 | 9.4 | 0.01 | Apr 18, 2023 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version… | ||
| CVE-2023-28863 | Cri | 0.59 | 9.1 | 0.00 | Apr 18, 2023 | AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity. | ||
| CVE-2022-46640 | Cri | 0.64 | 9.8 | 0.02 | Apr 18, 2023 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. | ||
| CVE-2021-40507 | Cri | 0.00 | 9.8 | 0.01 | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on… | ||
| CVE-2021-40506 | Cri | 0.00 | 9.8 | 0.01 | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this… | ||
| CVE-2023-2138 | Cri | 0.57 | 9.8 | 0.01 | Apr 18, 2023 | Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. | ||
| CVE-2023-30547 | Cri | 0.62 | 9.8 | 0.72 | Apr 17, 2023 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used… | ||
| CVE-2023-29213 | Cri | 0.52 | 9.0 | 0.00 | Apr 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into visiting a constructed url where e.g., by… | ||
| CVE-2023-24501 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. | ||
| CVE-2021-33797 | Cri | 0.00 | 9.8 | 0.01 | Apr 17, 2023 | Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d. | ||
| CVE-2023-30769 | Cri | 0.59 | 9.1 | 0.01 | Apr 17, 2023 | Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and take them offline. An attacker can crawl the network peers using getaddr message and attack the unpatched nodes. | ||
| CVE-2023-29665 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings. | ||
| CVE-2023-1873 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05. | ||
| CVE-2023-27844 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component. | ||
| CVE-2023-1723 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343. | ||
| CVE-2023-30771 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version… | ||
| CVE-2023-24831 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4. | |
| CVE-2023-30537 | Cri | 0.57 | 9.9 | 0.01 | Apr 16, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root… | ||
| CVE-2023-29511 | Cri | 0.57 | 9.9 | 0.01 | Apr 16, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki… | ||
| CVE-2023-29509 | Cri | 0.63 | 9.9 | 0.76 | Apr 16, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is… | ||
| CVE-2023-29507 | Cri | 0.52 | 9.1 | 0.01 | Apr 16, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is… | ||
| CVE-2023-29214 | Cri | 0.57 | 9.9 | 0.01 | Apr 16, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included… | ||
| CVE-2023-29212 | Cri | 0.57 | 9.9 | 0.01 | Apr 16, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included… | ||
| CVE-2023-29211 | Cri | 0.57 | 9.9 | 0.01 | Apr 16, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper… | ||
| CVE-2022-48312 | Cri | 0.59 | 9.1 | 0.00 | Apr 16, 2023 | The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2021-33990 | Cri | 0.68 | 9.8 | 0.12 | Apr 16, 2023 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can… | ||
| CVE-2022-34128 | Cri | 0.67 | 9.8 | 0.08 | Apr 16, 2023 | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. | ||
| CVE-2018-17452 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2023 | An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb. |
- risk 0.64cvss 9.8epss 0.01
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…
- risk 0.65cvss 10.0epss 0.03
Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.
- risk 0.65cvss 10.0epss 0.01
Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.
- risk 0.65cvss 10.0epss 0.01
Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.
- risk 0.64cvss 9.8epss 0.00
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L…
- risk 0.75cvss 9.6epss 0.06
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.64cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groovy script content. Viewing…
- risk 0.64cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either…
- risk 0.64cvss 9.9epss 0.78
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint.…
- risk 0.70cvss 9.9epss 0.76
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your user profile with the object…
- risk 0.58cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted…
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access…
- risk 0.52cvss 9.0epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a…
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping…
- risk 0.63cvss 9.9epss 0.66
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The…
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on any document (e.g., their own user profile) can execute code with programming rights, leading to remote code execution. This vulnerability has…
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki…
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such translations are often included…
- risk 0.64cvss 9.8epss 0.01
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
- risk 0.64cvss 9.8epss 0.01
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
- risk 0.64cvss 9.8epss 0.01
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
- risk 0.00cvss 9.4epss 0.01
Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version…
- risk 0.59cvss 9.1epss 0.00
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
- risk 0.64cvss 9.8epss 0.02
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on…
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this…
- risk 0.57cvss 9.8epss 0.01
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
- risk 0.62cvss 9.8epss 0.72
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used…
- risk 0.52cvss 9.0epss 0.00
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into visiting a constructed url where e.g., by…
- risk 0.64cvss 9.8epss 0.01
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
- risk 0.00cvss 9.8epss 0.01
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
- risk 0.59cvss 9.1epss 0.01
Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and take them offline. An attacker can crawl the network peers using getaddr message and attack the unpatched nodes.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343.
- risk 0.64cvss 9.8epss 0.01
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version…
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4.
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root…
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki…
- risk 0.63cvss 9.9epss 0.76
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is…
- risk 0.52cvss 9.1epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is…
- risk 0.57cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included…
- risk 0.57cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included…
- risk 0.57cvss 9.9epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper…
- risk 0.59cvss 9.1epss 0.00
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.68cvss 9.8epss 0.12
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can…
- risk 0.67cvss 9.8epss 0.08
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.