Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 [1179] 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 ... Result(s) : 43697

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2018-05-29 CVE-2015-9235 cve In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms ...
9.8 2018-05-29 CVE-2015-9244 cve Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
9.8 2018-05-29 CVE-2016-10525 cve When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
9.8 2018-05-29 CVE-2016-10551 cve waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith`...
9.8 2018-05-29 CVE-2018-10466 cve Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
9.8 2018-05-29 CVE-2018-11544 cve The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_p...
9.8 2018-05-29 CVE-2018-11545 cve md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.
9.8 2018-05-29 CVE-2018-11546 cve md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.
9.8 2018-05-29 CVE-2018-11547 cve md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.
9.8 2018-05-29 CVE-2018-3744 cve The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
9.1 2018-05-29 CVE-2018-3745 cve atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
9.8 2018-05-28 CVE-2018-11309 cve Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCo...
9.8 2018-05-28 CVE-2018-11515 cve The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
9.8 2018-05-26 CVE-2018-11499 cve A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (applic...
9.8 2018-05-26 CVE-2018-6410 cve An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
9.8 2018-05-26 CVE-2018-6411 cve An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter i...
9.8 2018-05-25 CVE-2018-11444 cve A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
9.8 2018-05-25 CVE-2018-8871 cve In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code ...
9.8 2018-05-25 CVE-2018-9091 cve A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management co...
9.8 2018-05-24 CVE-2018-11410 cve An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (applicat...
Page(s) : 1 ... 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 [1179] 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 ... Result(s) : 43697