Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 534 535 536 537 538 539 540 541 542 543 [544] 545 546 547 548 549 550 551 552 553 554 ... Result(s) : 43430

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2022-08-02 CVE-2020-28434 cve This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
9.8 2022-08-02 CVE-2020-28425 cve This affects all versions of package curljs.
9.8 2022-08-02 CVE-2020-28424 cve This affects all versions of package s3-kilatstorage.
9.8 2022-08-02 CVE-2020-28423 cve This affects all versions of package monorepo-build.
9.1 2022-08-02 CVE-2022-35924 cve NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or...
9.8 2022-08-02 CVE-2022-30285 cve In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
9.8 2022-08-02 CVE-2022-29807 cve A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
9.8 2022-08-02 CVE-2020-28433 cve This affects all versions of package node-latex-pdf.
9.8 2022-08-01 CVE-2022-31180 cve Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only im...
9.8 2022-08-01 CVE-2022-31179 cve Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (an...
9.8 2022-08-01 CVE-2022-31181 cve PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to ca...
9.8 2022-08-01 CVE-2022-31183 cve fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, pe...
9.8 2022-08-01 CVE-2022-31188 cve CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) v...
9.1 2022-08-01 CVE-2022-31321 cve The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) ...
9.8 2022-08-01 CVE-2022-27255 cve In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code wi...
9.8 2022-08-01 CVE-2022-2317 cve The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
9.8 2022-08-01 CVE-2022-1950 cve The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, lead...
9.8 2022-08-01 CVE-2022-26437 cve In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges neede...
9.1 2022-08-01 CVE-2022-31775 cve IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) ...
10 2022-08-01 CVE-2022-2595 cve Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
Page(s) : 1 ... 534 535 536 537 538 539 540 541 542 543 [544] 545 546 547 548 549 550 551 552 553 554 ... Result(s) : 43430