Show filters
1,297 Total Results
Displaying 101-110 of 1,297
Sort by:
Attacker Value
Unknown

CVE-2024-0355

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250122 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-47473

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.
Attacker Value
Unknown

CVE-2023-50783

Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification. Users are recommended to upgrade to 2.8.0, which fixes this issue
Attacker Value
Unknown

CVE-2023-49920

Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to trigger the execution of DAGs without the user's consent. Users are advised to upgrade to version 2.8.0 or later which is not affected
Attacker Value
Unknown

CVE-2023-48291

Disclosure Date: December 21, 2023 (last updated December 29, 2023)
Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus, enabling the user to clear DAGs they shouldn't. This is a missing fix for CVE-2023-42792 in Apache Airflow 2.7.2  Users of Apache Airflow are strongly advised to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability.
Attacker Value
Unknown

CVE-2023-47265

Disclosure Date: December 21, 2023 (last updated February 14, 2025)
Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of the user who looks at the tasks in the browser sandbox. While this issue does not allow to exit the browser sandbox or manipulation of the server-side data - more than the DAG author already has, it allows to modify what the user looking at the DAG details sees in the browser - which opens up all kinds of possibilities of misleading other users. Users of Apache Airflow are recommended to upgrade to version 2.8.0 or newer to mitigate the risk associated with this vulnerability
Attacker Value
Unknown

CVE-2023-49816

Disclosure Date: December 17, 2023 (last updated December 20, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Innovative Solutions Fix My Feed RSS Repair.This issue affects Fix My Feed RSS Repair: from n/a through 1.4.
Attacker Value
Unknown

CVE-2023-47037

Disclosure Date: November 12, 2023 (last updated February 14, 2025)
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
Attacker Value
Unknown

CVE-2023-42781

Disclosure Date: November 12, 2023 (last updated November 21, 2023)
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.
Attacker Value
Unknown

CVE-2023-4804

Disclosure Date: November 10, 2023 (last updated November 17, 2023)
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.