Medium · CVSS 6.1
CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
Published Nov 3, 2022 · Updated May 5, 2025
Medium · CVSS 6.1
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
Published Nov 3, 2022 · Updated May 5, 2025
Medium · CVSS 6.1
CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 8.8
CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 8.8
CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.
Published Nov 3, 2022 · Updated May 5, 2025
Medium · CVSS 6.1
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 7.2
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 7.2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 7.2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
Published Nov 3, 2022 · Updated May 5, 2025
Critical · CVSS 9.8
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
Published Nov 3, 2022 · Updated May 5, 2025
Medium · CVSS 4.8
Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.
Published Nov 3, 2022 · Updated May 5, 2025
High · CVSS 7.5
open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.5
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.5
open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.
Published Nov 1, 2022 · Updated May 2, 2025
High · CVSS 7.2
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.
Published Nov 2, 2022 · Updated May 2, 2025
High · CVSS 7.2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message.
Published Nov 2, 2022 · Updated May 2, 2025
High · CVSS 7.2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
Published Nov 2, 2022 · Updated May 2, 2025
High · CVSS 8.8
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 5.5
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 5.5
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 5.4
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.1
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
Published Nov 2, 2022 · Updated May 2, 2025
Medium · CVSS 6.1
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
Published Nov 2, 2022 · Updated May 2, 2025
High · CVSS 7.5
A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.
Published Nov 3, 2022 · Updated May 2, 2025
Medium · CVSS 6.5
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."
Published Nov 3, 2022 · Updated May 2, 2025
Medium · CVSS 4.3
"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1 could disclose sensitive version information to authenticated users which could be used in further attacks against the system. IBM X-Force ID: 230537."
Published Nov 3, 2022 · Updated May 2, 2025
Medium · CVSS 5.4
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592."
Published Nov 3, 2022 · Updated May 2, 2025
High · CVSS 7.8
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published Nov 3, 2022 · Updated May 2, 2025