CVE-2020-28443

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.Read More ...

Continue Reading
CVE-2022-2131

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external e ...

Continue Reading
CVE-2022-2523

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.Read More ...

Continue Reading
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volume ...

Continue Reading
CVE-2021-23451

The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.Read More ...

Continue Reading
CVE-2021-23397

All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.Read More ...

Continue Reading
CVE-2021-23373

All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.Read More ...

Continue Reading
CVE-2020-7678

This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located ...

Continue Reading

Back to Main

Subscribe for the latest news: