| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42637 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. | |
| CVE-2024-42634 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2024 | A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges. | ||
| CVE-2024-42466 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9. | ||
| CVE-2024-42465 | Cri | 0.64 | 9.8 | 0.00 | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9. | ||
| CVE-2024-42462 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9. | ||
| CVE-2024-6460 | Cri | 0.64 | 9.8 | 0.05 | Aug 16, 2024 | The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files. | ||
| CVE-2024-42757 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page. | ||
| CVE-2024-42472 | Cri | 0.00 | 10.0 | 0.01 | Aug 15, 2024 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on… | ||
| CVE-2024-27730 | Cri | 0.00 | 9.8 | 0.01 | Aug 15, 2024 | Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature. | ||
| CVE-2024-23168 | Cri | 0.64 | 9.8 | 0.00 | Aug 15, 2024 | Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution. | ||
| CVE-2024-42978 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request. | ||
| CVE-2024-42967 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh. | ||
| CVE-2024-42966 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh. | ||
| CVE-2024-42947 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request. | ||
| CVE-2024-42843 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php. | ||
| CVE-2024-42360 | Cri | 0.57 | 9.8 | 0.01 | Aug 14, 2024 | SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This… | ||
| CVE-2024-5914 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2024 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | ||
| CVE-2024-39397 | Cri | 0.59 | 9.0 | 0.01 | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a… | ||
| CVE-2024-7732 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2024 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. | ||
| CVE-2024-7731 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2024 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents. | ||
| CVE-2024-38652 | Cri | 0.60 | 9.1 | 0.08 | Aug 14, 2024 | Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion. | ||
| CVE-2024-20083 | Cri | 0.64 | 9.8 | 0.00 | Aug 14, 2024 | In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502. | ||
| CVE-2024-20082 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2024 | In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529. | ||
| CVE-2024-28986 | Cri | 0.82 | 9.8 | 0.85 | KEV | Aug 13, 2024 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been… | |
| CVE-2024-7593 | Cri | 0.87 | 9.8 | 1.00 | KEV | Aug 13, 2024 | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | |
| CVE-2024-7569 | Cri | 0.63 | 9.6 | 0.02 | Aug 13, 2024 | An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information. | ||
| CVE-2024-38199 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2024 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | ||
| CVE-2024-38160 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability | ||
| CVE-2024-38159 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability | ||
| CVE-2024-38140 | Cri | 0.64 | 9.8 | 0.04 | Aug 13, 2024 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-38109 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | ||
| CVE-2024-38108 | Cri | 0.61 | 9.3 | 0.01 | Aug 13, 2024 | Azure Stack Hub Spoofing Vulnerability | ||
| CVE-2024-38063 | Cri | 0.69 | 9.8 | 0.71 | Aug 13, 2024 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2024-7746 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication… | ||
| CVE-2024-41623 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload | ||
| CVE-2024-43160 | Cri | 0.65 | 10.0 | 0.05 | Aug 13, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6. | ||
| CVE-2024-43153 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10. | ||
| CVE-2024-43141 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2. | ||
| CVE-2024-37287 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution. | ||
| CVE-2024-43121 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2024 | Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1. | ||
| CVE-2024-41940 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges. | ||
| CVE-2024-41730 | Cri | 0.70 | 9.8 | 0.76 | Aug 13, 2024 | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality,… | ||
| CVE-2024-7094 | Cri | 0.67 | 9.8 | 0.38 | Aug 13, 2024 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on… | ||
| CVE-2024-43360 | Cri | 0.00 | 9.8 | 0.06 | Aug 12, 2024 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61. | ||
| CVE-2024-42547 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function. | ||
| CVE-2024-42546 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function. | ||
| CVE-2024-42545 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function. | ||
| CVE-2024-42543 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function. | ||
| CVE-2024-42489 | Cri | 0.00 | 10.0 | 0.01 | Aug 12, 2024 | Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind… | ||
| CVE-2023-7249 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. |
- risk 0.64cvss 9.8epss 0.01
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.02
A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.
- risk 0.64cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
- risk 0.64cvss 9.8epss 0.00
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
- risk 0.64cvss 9.8epss 0.01
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
- risk 0.64cvss 9.8epss 0.05
The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
- risk 0.64cvss 9.8epss 0.01
Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.
- risk 0.00cvss 10.0epss 0.01
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on…
- risk 0.00cvss 9.8epss 0.01
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.
- risk 0.64cvss 9.8epss 0.00
Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
- risk 0.64cvss 9.8epss 0.01
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.
- risk 0.57cvss 9.8epss 0.01
SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This…
- risk 0.64cvss 9.8epss 0.01
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
- risk 0.59cvss 9.0epss 0.01
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a…
- risk 0.64cvss 9.8epss 0.01
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
- risk 0.64cvss 9.8epss 0.01
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
- risk 0.60cvss 9.1epss 0.08
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
- risk 0.64cvss 9.8epss 0.00
In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.
- risk 0.64cvss 9.8epss 0.01
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529.
- risk 0.82cvss 9.8epss 0.85
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been…
- risk 0.87cvss 9.8epss 1.00
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- risk 0.63cvss 9.6epss 0.02
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
- risk 0.64cvss 9.8epss 0.02
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.02
Windows Network Virtualization Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.02
Windows Network Virtualization Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.02
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
- risk 0.61cvss 9.3epss 0.01
Azure Stack Hub Spoofing Vulnerability
- risk 0.69cvss 9.8epss 0.71
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication…
- risk 0.64cvss 9.8epss 0.01
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload
- risk 0.65cvss 10.0epss 0.05
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.
- risk 0.64cvss 9.8epss 0.01
Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.
- risk 0.59cvss 9.1epss 0.02
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.
- risk 0.59cvss 9.1epss 0.00
Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.
- risk 0.59cvss 9.1epss 0.01
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.
- risk 0.70cvss 9.8epss 0.76
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality,…
- risk 0.67cvss 9.8epss 0.38
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on…
- risk 0.00cvss 9.8epss 0.06
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- risk 0.00cvss 10.0epss 0.01
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind…
- risk 0.64cvss 9.8epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.