Medium · CVSS 4.3
An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related configuration.
Published Aug 6, 2021 · Updated Oct 25, 2024
Critical · CVSS 9.8
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying malicious web application archive files using the default hard-coded Tomcat Manager username and password.
Published Aug 18, 2021 · Updated Oct 25, 2024
Medium · CVSS 5.8
An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote and unauthenticated attacker to perform an XSS attack via sending a crafted request with an invalid lang parameter or with an invalid org.springframework.web.servlet.i18n.CookieLocaleResolver.LOCALE value.
Published Aug 18, 2021 · Updated Oct 25, 2024
Unknown · CVSS Not scored
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
Published Aug 7, 2023 · Updated Oct 15, 2024
Medium · CVSS 5.5
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.
Published Aug 23, 2022 · Updated Oct 15, 2024
High · CVSS 7.8
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.
Published Aug 8, 2023 · Updated Oct 11, 2024
High · CVSS 7.5
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0.
Published Aug 30, 2021 · Updated Oct 11, 2024
Unknown · CVSS Not scored
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field.
Published Aug 30, 2021 · Updated Oct 11, 2024
Unknown · CVSS Not scored
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field.
Published Aug 30, 2021 · Updated Oct 11, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1.
Published Aug 25, 2021 · Updated Oct 11, 2024
Unknown · CVSS Not scored
vim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the ex_buffer_all method.
Published Aug 11, 2023 · Updated Oct 10, 2024
Unknown · CVSS Not scored
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitrary code via the embed media feature.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).
Published Aug 11, 2023 · Updated Oct 9, 2024
High · CVSS 7.8
Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.
Published Aug 11, 2023 · Updated Oct 9, 2024
High · CVSS 7.8
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
Published Aug 11, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
Published Aug 13, 2023 · Updated Oct 9, 2024
Unknown · CVSS Not scored
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Published Aug 22, 2023 · Updated Oct 4, 2024
Unknown · CVSS Not scored
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.
Published Aug 22, 2023 · Updated Oct 4, 2024
High · CVSS 7.5
dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of the application server to install malicious applications on user's systems by altering the server's API response.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.
Published Aug 22, 2023 · Updated Oct 3, 2024
Unknown · CVSS Not scored
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
Published Aug 25, 2023 · Updated Oct 2, 2024
High · CVSS 7.8
Windows Graphics Component Remote Code Execution Vulnerability
Published Aug 12, 2021 · Updated Oct 1, 2024
High · CVSS 8.8
Windows Print Spooler Remote Code Execution Vulnerability
Published Aug 12, 2021 · Updated Oct 1, 2024
Low · CVSS 2.5
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISI_PRIV_LOGIN_CONSOLE or ISI_PRIV_LOGIN_SSH privileges to gain access up to 24 bytes of data within the /ifs kernel stack under certain conditions.
Published Aug 16, 2021 · Updated Sep 17, 2024
Medium · CVSS 4.6
OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attacker could exploit this vulnerability by injecting arbitrary code via de uuid parameter.
Published Aug 30, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.2
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.
Published Aug 4, 2021 · Updated Sep 17, 2024