Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown

CVE-2024-49756

Disclosure Date: October 23, 2024 (last updated October 24, 2024)
AshPostgres is the PostgreSQL data layer for Ash Framework. Starting in version 2.0.0 and prior to version 2.4.10, in certain very specific situations, it was possible for the policies of an update action to be skipped. This occurred only on "empty" update actions (no changing fields), and would allow their hooks (side effects) to be performed when they should not have been. Note that this does not allow reading new data that the user should not have had access to, only triggering a side effect a user should not have been able to trigger. To be vulnerable, an affected user must have an update action that is on a resource with no attributes containing an "update default" (updated_at timestamp, for example); can be performed atomically; does not have `require_atomic? false`; has at least one authorizer (typically `Ash.Policy.Authorizer`); and has at least one `change` (on the resource's `changes` block or in the action itself). This is where the side-effects would be performed when the…
0
Attacker Value
Unknown

CVE-2023-24205

Disclosure Date: February 23, 2023 (last updated October 08, 2023)
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).
Attacker Value
Unknown

CVE-2015-10069

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
A vulnerability was found in viakondratiuk cash-machine. It has been declared as critical. This vulnerability affects the function is_card_pin_at_session/update_failed_attempts of the file machine.py. The manipulation leads to sql injection. The name of the patch is 62a6e24efdfa195b70d7df140d8287fdc38eb66d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218896.
Attacker Value
Unknown

CVE-2018-25051

Disclosure Date: December 28, 2022 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in JmPotato Pomash. This affects an unknown part of the file Pomash/theme/clean/templates/editor.html. The manipulation of the argument article.title/content.title/article.tag leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is be1914ef0a6808e00f51618b2de92496a3604415. It is recommended to apply a patch to fix this issue. The identifier VDB-216957 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-4735

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 24d01757a5319cc14c4aa1d8b53d1ab24d48e451. It is recommended to apply a patch to fix this issue. VDB-216766 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-40126

Disclosure Date: September 29, 2022 (last updated October 08, 2023)
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
Attacker Value
Unknown

CVE-2022-31520

Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-31354

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.
Attacker Value
Unknown

CVE-2022-31353

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=.
Attacker Value
Unknown

CVE-2022-31352

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.