| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41657 | Cri | 0.65 | 9.8 | 0.21 | Oct 31, 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations… | ||
| CVE-2022-40202 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2022 | The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function… | ||
| CVE-2022-38142 | Cri | 0.65 | 9.8 | 0.18 | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon… | ||
| CVE-2022-31692 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2022 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring… | ||
| CVE-2022-27583 | Cri | 0.59 | 9.1 | 0.01 | Oct 31, 2022 | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact. | ||
| CVE-2022-40471 | Cri | 0.68 | 9.8 | 0.19 | Oct 31, 2022 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php | ||
| CVE-2022-3254 | Cri | 0.64 | 9.8 | 0.05 | Oct 31, 2022 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | ||
| CVE-2021-40241 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2022 | xfig 3.2.7 is vulnerable to Buffer Overflow. | ||
| CVE-2020-21016 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2022 | D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php. | ||
| CVE-2022-37623 | — | Cri | 0.57 | 9.8 | 0.01 | Oct 31, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. | |
| CVE-2022-40741 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2022 | Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service. | ||
| CVE-2021-42777 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2022 | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start. | ||
| CVE-2022-3754 | — | Cri | 0.57 | 9.8 | 0.01 | Oct 29, 2022 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | |
| CVE-2022-43286 | Cri | 0.00 | 9.8 | 0.01 | Oct 28, 2022 | Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. | ||
| CVE-2022-37621 | — | Cri | 0.57 | 9.8 | 0.01 | Oct 28, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. | |
| CVE-2022-3708 | Cri | 0.55 | 9.6 | 0.01 | Oct 28, 2022 | The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for… | ||
| CVE-2022-41648 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on… | ||
| CVE-2022-41636 | Cri | 0.59 | 9.1 | 0.00 | Oct 28, 2022 | Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive information being passed to and from the controller. | ||
| CVE-2022-2475 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources… | ||
| CVE-2022-2474 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized… | ||
| CVE-2022-43168 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. | ||
| CVE-2022-39366 | Cri | 0.57 | 9.9 | 0.01 | Oct 28, 2022 | DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service… | ||
| CVE-2022-37425 | Cri | 0.64 | 9.9 | 0.02 | Oct 28, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | ||
| CVE-2021-38733 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | ||
| CVE-2021-38732 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | ||
| CVE-2021-38731 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | ||
| CVE-2021-38730 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | ||
| CVE-2021-38729 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | ||
| CVE-2021-38217 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. | ||
| CVE-2021-38737 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. | ||
| CVE-2021-38736 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. | ||
| CVE-2021-38734 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. | ||
| CVE-2021-37782 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. | ||
| CVE-2022-3741 | Cri | 0.00 | 9.8 | 0.01 | Oct 28, 2022 | Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to… | ||
| CVE-2022-37915 | Cri | 0.64 | 9.8 | 0.02 | Oct 28, 2022 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability could allow an attacker to execute… | ||
| CVE-2022-37914 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges… | ||
| CVE-2022-37913 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges… | ||
| CVE-2022-31678 | Cri | 0.60 | 9.1 | 0.08 | Oct 28, 2022 | VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure. | ||
| CVE-2021-38397 | Cri | 0.65 | 10.0 | 0.01 | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | ||
| CVE-2021-38395 | Cri | 0.59 | 9.1 | 0.01 | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition. | ||
| CVE-2021-36206 | Cri | 0.65 | 10.0 | 0.00 | Oct 28, 2022 | All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries. | ||
| CVE-2022-40876 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2022 | In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE). | ||
| CVE-2022-3386 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution. | ||
| CVE-2022-3385 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution. | ||
| CVE-2022-39976 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | ||
| CVE-2022-43367 | Cri | 0.64 | 9.8 | 0.05 | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function. | ||
| CVE-2022-3095 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2022 | The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to… | ||
| CVE-2022-39365 | Cri | 0.57 | 9.8 | 0.02 | Oct 27, 2022 | Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.… | ||
| CVE-2022-2782 | Cri | 0.59 | 9.1 | 0.01 | Oct 27, 2022 | In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters. | ||
| CVE-2022-3363 | — | Cri | 0.57 | 9.8 | 0.01 | Oct 26, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. |
- risk 0.65cvss 9.8epss 0.21
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be used in API operations…
- risk 0.64cvss 9.8epss 0.01
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function…
- risk 0.65cvss 9.8epss 0.18
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon…
- risk 0.64cvss 9.8epss 0.03
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring…
- risk 0.59cvss 9.1epss 0.01
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
- risk 0.68cvss 9.8epss 0.19
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
- risk 0.64cvss 9.8epss 0.05
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
- risk 0.64cvss 9.8epss 0.01
xfig 3.2.7 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.
- risk 0.64cvss 9.8epss 0.01
Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.
- risk 0.64cvss 9.8epss 0.01
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.
- risk 0.57cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- risk 0.00cvss 9.8epss 0.01
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.
- risk 0.55cvss 9.6epss 0.01
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validation of URLs supplied via the 'url' parameter found via the /v1/hotlink/proxy REST API Endpoint. This makes it possible for…
- risk 0.64cvss 9.8epss 0.01
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on…
- risk 0.59cvss 9.1epss 0.00
Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive information being passed to and from the controller.
- risk 0.64cvss 9.8epss 0.01
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources…
- risk 0.64cvss 9.8epss 0.01
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized…
- risk 0.64cvss 9.8epss 0.01
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.
- risk 0.57cvss 9.9epss 0.01
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service…
- risk 0.64cvss 9.9epss 0.02
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
- risk 0.64cvss 9.8epss 0.01
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
- risk 0.00cvss 9.8epss 0.01
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability could allow an attacker to execute…
- risk 0.64cvss 9.8epss 0.01
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges…
- risk 0.64cvss 9.8epss 0.01
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges…
- risk 0.60cvss 9.1epss 0.08
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
- risk 0.65cvss 10.0epss 0.01
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
- risk 0.59cvss 9.1epss 0.01
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
- risk 0.65cvss 10.0epss 0.00
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
- risk 0.64cvss 9.8epss 0.02
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
- risk 0.64cvss 9.8epss 0.01
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.
- risk 0.64cvss 9.8epss 0.01
Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.
- risk 0.64cvss 9.8epss 0.01
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.05
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
- risk 0.64cvss 9.8epss 0.01
The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to…
- risk 0.57cvss 9.8epss 0.02
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…
- risk 0.59cvss 9.1epss 0.01
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.