Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 574 575 576 577 578 579 580 581 582 583 [584] 585 586 587 588 589 590 591 592 593 594 ... Result(s) : 43431

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2022-05-26 CVE-2022-29660 cve CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
9.8 2022-05-26 CVE-2022-30474 cve Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.
9.8 2022-05-26 CVE-2021-33016 cve An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product r...
9.1 2022-05-26 CVE-2022-1899 cve Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.
9.1 2022-05-26 CVE-2022-26693 cve This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.
9.8 2022-05-26 CVE-2022-26723 cve A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. Mounting a maliciously crafted Samba ne...
9.8 2022-05-26 CVE-2022-29633 cve An access control issue in Linglong v1.0 allows attackers to access the background of the application via a crafted cookie.
9.8 2022-05-26 CVE-2022-30472 cve Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
9.8 2022-05-26 CVE-2022-30500 cve Jfinal cms 5.1.0 is vulnerable to SQL Injection.
9.8 2022-05-25 CVE-2022-23775 cve TrueStack Direct Connect 1.4.7 has Incorrect Access Control.
9.8 2022-05-25 CVE-2022-26082 cve A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network...
9.1 2022-05-25 CVE-2021-27779 cve VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
9.8 2022-05-25 CVE-2022-30595 cve libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
9.8 2022-05-25 CVE-2022-29379 cve Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this rep...
9.8 2022-05-25 CVE-2022-26945 cve go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2...
9.8 2022-05-25 CVE-2022-28862 cve In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL stat...
9.4 2022-05-25 CVE-2022-26833 cve An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests c...
9.8 2022-05-25 CVE-2022-29361 cve Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests inc...
9.8 2022-05-25 CVE-2022-29650 cve Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
9.8 2022-05-24 CVE-2022-29334 cve An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
Page(s) : 1 ... 574 575 576 577 578 579 580 581 582 583 [584] 585 586 587 588 589 590 591 592 593 594 ... Result(s) : 43431