| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1887 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101. | ||
| CVE-2021-4140 | Cri | 0.65 | 10.0 | 0.01 | Dec 22, 2022 | It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | ||
| CVE-2021-4129 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough… | ||
| CVE-2021-4127 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9. | ||
| CVE-2022-47926 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php | ||
| CVE-2022-46102 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php | ||
| CVE-2022-45966 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | ||
| CVE-2022-45347 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has… | ||
| CVE-2022-3184 | Cri | 0.65 | 9.8 | 0.12 | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory. | ||
| CVE-2022-3183 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. | ||
| CVE-2022-40145 | — | Cri | 0.57 | 9.8 | 0.02 | Dec 21, 2022 | This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)… | |
| CVE-2022-47635 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2022 | Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php. | ||
| CVE-2022-25893 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2022 | The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise. | ||
| CVE-2022-47629 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. | ||
| CVE-2022-46327 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions. | ||
| CVE-2022-46326 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46325 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46324 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46323 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46320 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting. | ||
| CVE-2022-46319 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write. | ||
| CVE-2022-46316 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2022-46020 | Cri | 0.67 | 9.8 | 0.39 | Dec 20, 2022 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | ||
| CVE-2022-46538 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. | ||
| CVE-2022-40624 | Cri | 0.65 | 9.8 | 0.17 | Dec 20, 2022 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | ||
| CVE-2022-46421 | Cri | 0.57 | 9.8 | 0.03 | Dec 20, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | ||
| CVE-2022-44109 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int). | ||
| CVE-2022-44108 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. | ||
| CVE-2022-44940 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 19, 2022 | Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc. | |
| CVE-2022-40434 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | ||
| CVE-2022-28173 | Cri | 0.59 | 9.1 | 0.01 | Dec 19, 2022 | The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices. | ||
| CVE-2022-4063 | Cri | 0.64 | 9.8 | 0.10 | Dec 19, 2022 | The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers. | ||
| CVE-2022-4050 | Cri | 0.64 | 9.8 | 0.05 | Dec 19, 2022 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | ||
| CVE-2022-44755 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44754 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44753 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44752 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to… | ||
| CVE-2022-44751 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44750 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the… | ||
| CVE-2022-44456 | Cri | 0.69 | 9.8 | 0.70 | Dec 19, 2022 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. | ||
| CVE-2022-4606 | Cri | 0.03 | 9.8 | 0.35 | Dec 18, 2022 | PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. | ||
| CVE-2022-37832 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Mutiny 7.2.0-10788 suffers from Hardcoded root password. | ||
| CVE-2021-38241 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. | ||
| CVE-2021-31650 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter. | ||
| CVE-2022-45796 | Cri | 0.59 | 9.1 | 0.03 | Dec 16, 2022 | Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional… | ||
| CVE-2022-42529 | Cri | 0.64 | 9.8 | 0.00 | Dec 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A | ||
| CVE-2022-47377 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an… | ||
| CVE-2022-46393 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2022 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX. | ||
| CVE-2022-45969 | Cri | 0.57 | 9.8 | 0.01 | Dec 15, 2022 | Alist v3.4.0 is vulnerable to Directory Traversal, | ||
| CVE-2022-40004 | Cri | 0.62 | 9.6 | 0.01 | Dec 15, 2022 | Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log. |
- risk 0.64cvss 9.8epss 0.01
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
- risk 0.65cvss 10.0epss 0.01
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- risk 0.64cvss 9.8epss 0.01
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough…
- risk 0.64cvss 9.8epss 0.01
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
- risk 0.64cvss 9.8epss 0.01
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
- risk 0.64cvss 9.8epss 0.01
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
- risk 0.64cvss 9.8epss 0.01
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
- risk 0.64cvss 9.8epss 0.01
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has…
- risk 0.65cvss 9.8epss 0.12
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.
- risk 0.64cvss 9.8epss 0.02
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.
- risk 0.57cvss 9.8epss 0.02
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)…
- risk 0.64cvss 9.8epss 0.01
Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php.
- risk 0.64cvss 9.8epss 0.01
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
- risk 0.64cvss 9.8epss 0.02
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
- risk 0.64cvss 9.8epss 0.00
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
- risk 0.64cvss 9.8epss 0.00
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.67cvss 9.8epss 0.39
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
- risk 0.64cvss 9.8epss 0.02
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
- risk 0.65cvss 9.8epss 0.17
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
- risk 0.57cvss 9.8epss 0.03
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
- risk 0.64cvss 9.8epss 0.01
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int).
- risk 0.64cvss 9.8epss 0.01
pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.
- risk 0.52cvss 9.1epss 0.01
Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc.
- risk 0.64cvss 9.8epss 0.01
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
- risk 0.59cvss 9.1epss 0.01
The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
- risk 0.64cvss 9.8epss 0.10
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
- risk 0.64cvss 9.8epss 0.05
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to…
- risk 0.64cvss 9.8epss 0.01
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.64cvss 9.8epss 0.01
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…
- risk 0.69cvss 9.8epss 0.70
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
- risk 0.03cvss 9.8epss 0.35
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
- risk 0.64cvss 9.8epss 0.01
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
- risk 0.64cvss 9.8epss 0.01
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.
- risk 0.59cvss 9.1epss 0.03
Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional…
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
- risk 0.64cvss 9.8epss 0.01
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
- risk 0.57cvss 9.8epss 0.01
Alist v3.4.0 is vulnerable to Directory Traversal,
- risk 0.62cvss 9.6epss 0.01
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.