Show filters
141 Total Results
Displaying 1-10 of 141
Sort by:
Attacker Value
Very Low
CVE-2023-31484
Disclosure Date: April 29, 2023 (last updated October 08, 2023)
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
2
Attacker Value
Unknown
CVE-2024-49279
Disclosure Date: October 17, 2024 (last updated October 25, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TipTopPress Hyperlink Group Block allows Stored XSS.This issue affects Hyperlink Group Block: from n/a through 1.17.5.
0
Attacker Value
Unknown
CVE-2024-21545
Disclosure Date: September 25, 2024 (last updated September 25, 2024)
Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or 'VM.Monitor' privileges to download arbitrary host files via the API.
When handling the result from a request handler before returning it to the user, the handle_api2_request function will check for the ‘download’ or ‘data’->’download’ objects inside the request handler call response object. If present, handle_api2_request will read a local file defined by this object and return it to the user.
Two endpoints were identified which can control the object returned by a request handler sufficiently that the ’download’ object is defined and user controlled. This results in arbitrary file read.
The privileges of this file read can result in full compromise of the system by various impacts such as disclosing sensitive files allowing for privileged session forgery.
0
Attacker Value
Unknown
CVE-2024-6118
Disclosure Date: August 05, 2024 (last updated August 31, 2024)
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
0
Attacker Value
Unknown
CVE-2024-6117
Disclosure Date: August 05, 2024 (last updated August 31, 2024)
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
0
Attacker Value
Unknown
CVE-2024-35184
Disclosure Date: May 15, 2024 (last updated May 16, 2024)
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.
0
Attacker Value
Unknown
CVE-2023-47039
Disclosure Date: January 02, 2024 (last updated November 06, 2024)
A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe` within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place`cmd.exe` in locations with weak permissions, such as `C:\ProgramData`. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.
0
Attacker Value
Unknown
CVE-2023-47038
Disclosure Date: December 18, 2023 (last updated May 30, 2024)
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
0
Attacker Value
Unknown
CVE-2023-47100
Disclosure Date: December 02, 2023 (last updated December 09, 2023)
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
0
Attacker Value
Unknown
CVE-2022-48522
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.
0