Unknown · CVSS Not scored
Insufficient input validation in the ASP (AMD
Secure Processor) bootloader may allow an attacker with a compromised Uapp or
ABL to coerce the bootloader into exposing sensitive information to the SMU
(System Management Unit) resulting in a potential loss of confidentiality and
integrity.
Published May 9, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
Published May 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.
Published May 3, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.
Published May 24, 2022 · Updated Aug 4, 2024
Medium · CVSS 6
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
Published May 19, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.
Published May 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Docker Desktop 4.3.0 has Incorrect Access Control.
Published May 25, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.5
Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.
Published May 31, 2024 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
Published May 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
Published May 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
Published May 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
Published May 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.
Published May 20, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized Security Key parameter.
Published May 20, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.
Published May 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.
Published May 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
Published May 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data.
Published May 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.
Published May 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
Published May 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.
Published May 17, 2022 · Updated Aug 4, 2024
High · CVSS 8
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
Published May 18, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.3
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
Published May 18, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification
Published May 26, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.
Published May 12, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.8
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
Published May 18, 2022 · Updated Aug 4, 2024
High · CVSS 8.8
A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.
Published May 6, 2022 · Updated Aug 4, 2024
Medium · CVSS 4.3
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
Published May 18, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release
Published May 26, 2022 · Updated Aug 4, 2024
High · CVSS 8.8
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
Published May 18, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.
Published May 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
Published May 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
Published May 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
Published May 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.
Published May 26, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.
Published May 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
Published May 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.
Published May 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.
Published May 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
Published May 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes
Published May 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.
Published May 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
Published May 24, 2022 · Updated Aug 4, 2024