Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.Read More ...
Continue ReadingAugust 18, 2022
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().Read More ...
Continue ReadingAugust 18, 2022
lib/omniauth/failure_endpoint.rb in OmniAuth before 2.0 does not escape the message_key value.Read More ...
Continue ReadingAugust 18, 2022
This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...
Continue ReadingAugust 18, 2022
CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candi ...
Continue ReadingAugust 18, 2022
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.Read More ...
Continue ReadingAugust 18, 2022
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access.Read More ...
Continue ReadingAugust 18, 2022
Back to Main