CVE-2022-36722

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.Read More ...

Continue Reading
CVE-2022-35212

osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().Read More ...

Continue Reading
CVE-2020-36599

lib/omniauth/failure_endpoint.rb in OmniAuth before 2.0 does not escape the message_key value.Read More ...

Continue Reading
CVE-2022-35540

Hardcoded JWT Secret in AgileConfig Read More ...

Continue Reading
CVE-2022-0216

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2022-25228

CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candi ...

Continue Reading
CVE-2021-26254

Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.Read More ...

Continue Reading
CVE-2021-23188

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: