Show filters
79 Total Results
Displaying 11-20 of 79
Sort by:
Attacker Value
Unknown

CVE-2022-41990

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.
Attacker Value
Unknown

CVE-2023-50917

Disclosure Date: December 15, 2023 (last updated December 20, 2023)
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
Attacker Value
Unknown

CVE-2023-5915

Disclosure Date: December 01, 2023 (last updated December 09, 2023)
A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While sending the packet, the maintenance homepage of the controller could not be accessed. Therefore, functions of the maintenance homepage, changing configuration, viewing logs, etc. are not available. But the controller’s operation is not stopped by the condition. The affected products and versions are as follows: STARDOM FCN/FCJ R1.01 to R4.31.
Attacker Value
Unknown

CVE-2023-33865

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
Attacker Value
Unknown

CVE-2023-33864

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize.
Attacker Value
Unknown

CVE-2023-33863

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
Attacker Value
Unknown

CVE-2022-37939

Disclosure Date: March 10, 2023 (last updated November 08, 2023)
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locally exploited to allow disclosure of information. HPE has made the following software to resolve the vulnerability in HPE Superdome Flex Servers v3.65.8 and Superdome Flex 280 Servers v1.45.8.
Attacker Value
Unknown

CVE-2022-37933

Disclosure Date: January 05, 2023 (last updated November 08, 2023)
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome Flex firmware 3.60.50 and below and Superdome Flex 280 servers firmware 1.40.60 and below.
Attacker Value
Unknown

CVE-2022-25849

Disclosure Date: October 26, 2022 (last updated December 22, 2024)
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.
Attacker Value
Unknown

CVE-2022-31526

Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.