Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-41878 | 1 Parseplatform | 1 Parse-server | 2022-11-15 | N/A | 9.8 CRITICAL |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the `requestKeywordDenylist` option. This issue is fixed in versions 4.10.19, and 5.3.2. If upgrade is not possible, the following Workarounds may be applied: Configure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature. | |||||
CVE-2022-42460 | 1 Sedlex | 1 Traffic Manager | 2022-11-15 | N/A | 5.4 MEDIUM |
Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on WordPress. | |||||
CVE-2022-44089 | 1 Ecisp | 1 Espcms | 2022-11-15 | N/A | 9.8 CRITICAL |
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. | |||||
CVE-2022-44087 | 1 Ecisp | 1 Espcms | 2022-11-15 | N/A | 9.8 CRITICAL |
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. | |||||
CVE-2022-38122 | 1 Upspowercom | 1 Upsmon Pro | 2022-11-15 | N/A | 7.5 HIGH |
UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data. | |||||
CVE-2022-41879 | 1 Parseplatform | 1 Parse-server | 2022-11-15 | N/A | 9.8 CRITICAL |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server `requestKeywordDenylist` option. This issue has been patched in versions 5.3.3 and 4.10.20. There are no known workarounds. | |||||
CVE-2022-43679 | 1 Owncloud | 1 Owncloud | 2022-11-15 | N/A | 5.3 MEDIUM |
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages. | |||||
CVE-2022-3122 | 1 Clinic\'s Patient Management System Project | 1 Clinic\'s Patient Management System | 2022-11-15 | N/A | N/A |
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file medicine_details.php. The manipulation of the argument medicine leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207854 is the identifier assigned to this vulnerability. | |||||
CVE-2022-38120 | 1 Upspowercom | 1 Upsmon Pro | 2022-11-15 | N/A | 6.5 MEDIUM |
UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files. | |||||
CVE-2022-38119 | 1 Upspowercom | 1 Upsmon Pro | 2022-11-15 | N/A | 9.8 CRITICAL |
UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service. | |||||
CVE-2022-44727 | 1 Lineagrafica | 1 Eu Cookie Law Gdpr | 2022-11-15 | N/A | 9.1 CRITICAL |
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ). | |||||
CVE-2022-37623 | 1 Browserify-shim Project | 1 Browserify-shim | 2022-11-15 | N/A | 9.8 CRITICAL |
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. | |||||
CVE-2022-38577 | 1 Processmaker | 1 Processmaker | 2022-11-15 | N/A | 8.8 HIGH |
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. | |||||
CVE-2022-44088 | 1 Ecisp | 1 Espcms | 2022-11-15 | N/A | 9.8 CRITICAL |
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | |||||
CVE-2022-45130 | 1 Plesk | 1 Obsidian | 2022-11-15 | N/A | 6.5 MEDIUM |
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are identified by names ("Obsidian"), not numbers. | |||||
CVE-2021-40289 | 1 Mm-wki Project | 1 Mm-wki | 2022-11-15 | N/A | 6.1 MEDIUM |
mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS). | |||||
CVE-2022-39038 | 1 Flowring | 1 Agentflow | 2022-11-15 | N/A | 8.8 HIGH |
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service. | |||||
CVE-2022-39037 | 1 Flowring | 1 Agentflow | 2022-11-15 | N/A | 7.5 HIGH |
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |||||
CVE-2022-3867 | 1 Hashicorp | 1 Nomad | 2022-11-15 | N/A | 4.3 MEDIUM |
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2. | |||||
CVE-2022-3866 | 1 Hashicorp | 1 Nomad | 2022-11-15 | N/A | 4.3 MEDIUM |
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2. |