Unknown · CVSS Not scored
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.
Published Jun 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
Published Jun 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.
Published Jun 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.
Published Jun 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP server apply.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
Published Jun 10, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.
Published Jun 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
Published Jun 28, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
Published Jun 28, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.
Published Jun 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Published Jun 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
Published Jun 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
Published Jun 22, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
Published Jun 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
Published Jun 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).
Published Jun 28, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.
Published Jun 9, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.
Published Jun 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demonstrated by GPAC. This can cause a denial of service (DOS).
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
Published Jun 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
Published Jun 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
Published Jun 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).
Published Jun 28, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling crafted invalid rgb(a) strings.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
Published Jun 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
Published Jun 17, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.
Published Jun 24, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.
Published Jun 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
Published Jun 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Published Jun 14, 2022 · Updated Aug 4, 2024