CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2020-36560

    Last Modified: 11 Apr 2025

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2020-36559

    Last Modified: 11 Apr 2025

    Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2019-25073

    Last Modified: 11 Apr 2025

    Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2013-10005

    Last Modified: 11 Apr 2025

    The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which will crash the program due to a stack overflow.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2015-10004

    Last Modified: 11 Apr 2025

    Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.

    Published: 27 Dec 2022
    9.1
    Critical

    CVE-2020-36569

    Last Modified: 11 Apr 2025

    Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2020-36568

    Last Modified: 11 Apr 2025

    Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.

    Published: 27 Dec 2022
    7.8
    High

    CVE-2022-3156

    Last Modified: 10 Apr 2025

    A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4289

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. Affected by this vulnerability is the function post of the file omod/src/main/java/org/openmrs/module/referenceapplication/page/controller/UserAppPageController.java of the component User App Page. The manipulation of the argument AppId leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.12.0 is able to address this issue. The name of the patch is 0410c091d46eed3c132fe0fcafe5964182659f74. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216883.

    Published: 27 Dec 2022
    2.6
    Low

    CVE-2020-36634

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the function visit/appendTo of the file varexport/src/main/java/com/indeed/util/varexport/servlet/ViewExportedVariablesServlet.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.34 is able to address this issue. The name of the patch is c0952a9db51a880e9544d9fac2a2218a6bfc9c63. It is recommended to upgrade the affected component. VDB-216882 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4288

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. It has been rated as problematic. This issue affects some unknown processing of the file omod/src/main/webapp/pages/userApp.gsp. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.12.0 is able to address this issue. The name of the patch is 35f81901a4cb925747a9615b8706f5079d2196a1. It is recommended to upgrade the affected component. The identifier VDB-216881 was assigned to this vulnerability.

    Published: 27 Dec 2022
    4.3
    Medium

    CVE-2022-4766

    Last Modified: 21 Nov 2024

    A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address this issue. The name of the patch is 082282e9dab43963e6c8f03cfaddd7921de377f4. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216880.

    Published: 27 Dec 2022
    4.3
    Medium

    CVE-2020-36633

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this issue. The name of the patch is cd18d8b1afe464ae6626832496f4e070bac4c58f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216879.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2019-25090

    Last Modified: 21 Nov 2024

    A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl leads to cross site scripting. The attack may be launched remotely. Upgrading to version 13.0.5.4 is able to address this issue. The name of the patch is 199dea7cc7020d3c469a86a39fbd80f5edd3c5ab. It is recommended to upgrade the affected component. VDB-216878 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.1
    Low

    CVE-2019-25089

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. The manipulation leads to insufficiently random values. The attack can be launched remotely. Upgrading to version 0.2.0-indev is able to address this issue. The name of the patch is c09ed972c020f759110c707b06ca2644f0bacd7f. It is recommended to upgrade the affected component. The identifier VDB-216877 was assigned to this vulnerability.

    Published: 27 Dec 2022
    5
    Medium

    CVE-2021-4287

    Last Modified: 11 Apr 2025

    A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is possible to launch the attack remotely. Upgrading to version 2.3.3 is able to address this issue. The name of the patch is fa0c0bd59b8588814756942fe4cb5452e76c1dcd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216876.

    Published: 27 Dec 2022
    2.6
    Low

    CVE-2021-4286

    Last Modified: 11 Apr 2025

    A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The manipulation leads to information exposure through discrepancy. Upgrading to version 1.0.17 is able to address this issue. The name of the patch is dba52642f5e95d3da7af1780561213ee6053195f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216875.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4285

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.4.0 is able to address this issue. The name of the patch is 5abbcd7aa26e0fc815e6b2b0ffe1c15ef3e8fab5. It is recommended to upgrade the affected component. VDB-216874 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4284

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 811990972ea07649ae33c4b56c61c3b520895f07. It is recommended to upgrade the affected component. The identifier VDB-216873 was assigned to this vulnerability.

    Published: 27 Dec 2022
    2.4
    Low

    CVE-2021-4283

    Last Modified: 21 Nov 2024

    A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to version 14.0.6.25 is able to address this issue. The name of the patch is ffce4882016076acd16fe0f676246905aa3cb2f3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216872.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2021-4282

    Last Modified: 21 Nov 2024

    A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this issue. The name of the patch is 12e1469ef9208eda9d8955206e78345949236ee6. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216871.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2019-25088

    Last Modified: 21 Nov 2024

    A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2022-4755

    Last Modified: 21 Nov 2024

    A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to cross site scripting. The attack may be initiated remotely. The name of the patch is d3f329496536dc99f9707f2f295d571d65a496f5. It is recommended to apply a patch to fix this issue. The identifier VDB-216869 was assigned to this vulnerability.

    Published: 27 Dec 2022
    5.3
    Medium

    CVE-2019-25087

    Last Modified: 21 Nov 2024

    A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The name of the patch is 1a0de56e4dafff9c2f9c8f6b130a764f7a50df52. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216863.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2019-25086

    Last Modified: 21 Nov 2024

    A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.5.1 is able to address this issue. The name of the patch is 3f39f2d68d11895929c04f7b49b97a734ae7cd1f. It is recommended to upgrade the affected component. VDB-216862 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    5.5
    Medium

    CVE-2022-4748

    Last Modified: 21 Nov 2024

    A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5d5c7f6d8f072d14926fc2c3a97cdd763802f170. It is recommended to apply a patch to fix this issue. The identifier VDB-216861 was assigned to this vulnerability.

    Published: 27 Dec 2022
    3
    Low

    CVE-2018-25049

    Last Modified: 11 Apr 2025

    A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The name of the patch is 0029ba71b6ad0d8ec0baa2ecc6256d038bdd9b56. It is recommended to apply a patch to fix this issue. VDB-216854 is the identifier assigned to this vulnerability.

    Published: 27 Dec 2022
    3.5
    Low

    CVE-2015-10005

    Last Modified: 11 Apr 2025

    A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 89c8620157d6e38f9872811620d25138fc9d1b0d. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216852.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2022-46764

    Last Modified: 27 Feb 2026

    A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

    Published: 27 Dec 2022
    9.1
    Critical

    CVE-2018-25046

    Last Modified: 11 Apr 2025

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

    Published: 27 Dec 2022
    5.9
    Medium

    CVE-2022-45434

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

    Published: 27 Dec 2022
    3.7
    Low

    CVE-2022-45433

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results.

    Published: 27 Dec 2022
    5.3
    Medium

    CVE-2022-45432

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-45431

    Last Modified: 11 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server.

    Published: 27 Dec 2022
    3.7
    Low

    CVE-2022-45430

    Last Modified: 11 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the SSHD service.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2020-36567

    Last Modified: 11 Apr 2025

    Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2014-125026

    Last Modified: 11 Apr 2025

    LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

    Published: 27 Dec 2022
    5.5
    Medium

    CVE-2021-4235

    Last Modified: 11 Apr 2025

    Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

    Published: 27 Dec 2022
    9.1
    Critical

    CVE-2021-4238

    Last Modified: 11 Apr 2025

    Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2022-46442

    Last Modified: 11 Apr 2025

    dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2017-20146

    Last Modified: 11 Apr 2025

    Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-4767

    Last Modified: 10 Apr 2025

    Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

    Published: 27 Dec 2022
    5.4
    Medium

    CVE-2022-47968

    Last Modified: 11 Apr 2025

    Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.

    Published: 27 Dec 2022
    8.8
    High

    CVE-2022-46763

    Last Modified: 10 Feb 2026

    A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2022-45778

    Last Modified: 14 Apr 2025

    https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator privileges through a configuration error in report.m.

    Published: 27 Dec 2022
    9.8
    Critical

    CVE-2022-45963

    Last Modified: 11 Apr 2025

    h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-45423

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).

    Published: 27 Dec 2022
    5.3
    Medium

    CVE-2022-45424

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.

    Published: 27 Dec 2022
    7.5
    High

    CVE-2022-45425

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.

    Published: 27 Dec 2022
    6.5
    Medium

    CVE-2022-45426

    Last Modified: 14 Apr 2025

    Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary files.

    Published: 27 Dec 2022