Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php.Read More ...
Continue ReadingAugust 01, 2022
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an ...
Continue ReadingAugust 01, 2022
graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.Read More ...
Continue ReadingAugust 01, 2022
Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized payments into their apps and services. When a Solana Pay transaction is located using ...
Continue ReadingAugust 01, 2022
fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to versio ...
Continue ReadingAugust 01, 2022
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data ...
Continue ReadingAugust 01, 2022
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is no ...
Continue ReadingAugust 01, 2022
This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...
Continue ReadingAugust 01, 2022
Back to Main