Show filters
79 Total Results
Displaying 1-10 of 79
Sort by:
Attacker Value
Unknown
CVE-2023-22477
Disclosure Date: January 09, 2023 (last updated November 08, 2023)
Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions.
0
Attacker Value
Unknown
CVE-2022-43410
Disclosure Date: October 19, 2022 (last updated October 26, 2023)
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
0
Attacker Value
Unknown
CVE-2022-31517
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-30948
Disclosure Date: May 17, 2022 (last updated November 04, 2023)
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
0
Attacker Value
Unknown
CVE-2022-26988
Disclosure Date: May 10, 2022 (last updated October 07, 2023)
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
0
Attacker Value
Unknown
CVE-2022-26987
Disclosure Date: May 10, 2022 (last updated October 07, 2023)
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
0
Attacker Value
Unknown
CVE-2021-43801
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as v8.11.2. As a workaround users may use a custom error handler.
0
Attacker Value
Unknown
CVE-2021-25810
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
0
Attacker Value
Unknown
CVE-2021-25811
Disclosure Date: April 29, 2021 (last updated November 28, 2024)
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
0
Attacker Value
Unknown
CVE-2021-23242
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
0