Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-31177 | 1 Flask-appbuilder Project | 1 Flask-appbuilder | 2022-08-08 | N/A | 2.7 LOW |
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not include the hashed passwords, but an attacker could infer partial password hashes and their respective users. This issue has been fixed in version 4.1.3. Users are advised to upgrade. There are no known workarounds for this issue. | |||||
CVE-2022-0323 | 1 Mustache Project | 1 Mustache | 2022-08-08 | 6.5 MEDIUM | 8.8 HIGH |
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1. | |||||
CVE-2020-17437 | 4 Contiki-os, Open-iscsi Project, Siemens and 1 more | 21 Contiki, Open-iscsi, Sentron 3va Com100 and 18 more | 2022-08-08 | 6.4 MEDIUM | 8.2 HIGH |
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c. | |||||
CVE-2022-31155 | 1 Sourcegraph | 1 Sourcegraph | 2022-08-08 | N/A | 4.3 MEDIUM |
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with attacker-controlled searches. The issue is patched in Sourcegraph version 3.41.0. There is no workaround for this issue and updating to a secure version is highly recommended. | |||||
CVE-2022-31154 | 1 Sourcegraph | 1 Sourcegraph | 2022-08-08 | N/A | 4.3 MEDIUM |
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of existing code monitors, only override the data. The issue is fixed in Sourcegraph 3.42. There are no workaround for the issue and patching is highly recommended. | |||||
CVE-2022-34924 | 1 Landray | 1 Landray Office Automation | 2022-08-08 | N/A | 7.5 HIGH |
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp. | |||||
CVE-2022-1561 | 2 Krakend, Luraproject | 2 Krakend, Lura | 2022-08-08 | N/A | 4.3 MEDIUM |
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend might be vulnerable. | |||||
CVE-2022-36302 | 1 Bosch | 1 Bf-os | 2022-08-08 | N/A | 5.4 MEDIUM |
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information. | |||||
CVE-2022-36301 | 1 Bosch | 1 Bf-os | 2022-08-08 | N/A | 7.5 HIGH |
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. | |||||
CVE-2021-46680 | 1 Pandorafms | 1 Pandora Fms | 2022-08-06 | N/A | 6.1 MEDIUM |
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field. | |||||
CVE-2021-46679 | 1 Pandorafms | 1 Pandora Fms | 2022-08-06 | N/A | 6.1 MEDIUM |
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements. | |||||
CVE-2021-46678 | 1 Pandorafms | 1 Pandora Fms | 2022-08-06 | N/A | 6.1 MEDIUM |
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field. | |||||
CVE-2021-46677 | 1 Pandorafms | 1 Pandora Fms | 2022-08-06 | N/A | 6.1 MEDIUM |
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field. | |||||
CVE-2021-46676 | 1 Pandorafms | 1 Pandora Fms | 2022-08-06 | N/A | 6.1 MEDIUM |
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field. | |||||
CVE-2021-36861 | 1 Starfish | 1 Rich Review | 2022-08-06 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews. | |||||
CVE-2020-1754 | 1 Moodle | 1 Moodle | 2022-08-06 | N/A | 4.3 MEDIUM |
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups. | |||||
CVE-2020-1691 | 1 Moodle | 1 Moodle | 2022-08-06 | N/A | 5.4 MEDIUM |
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting. | |||||
CVE-2016-3098 | 1 Thoughtbot | 1 Administrate | 2022-08-06 | N/A | 5.4 MEDIUM |
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. | |||||
CVE-2022-2636 | 1 Hestiacp | 1 Control Panel | 2022-08-06 | N/A | 8.8 HIGH |
Improper Input Validation in GitHub repository hestiacp/hestiacp prior to 1.6.6. | |||||
CVE-2022-1961 | 1 Gtm4wp | 1 Google Tag Manager | 2022-08-05 | 3.5 LOW | 4.8 MEDIUM |
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. |