The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.Read More ...
Continue ReadingJuly 25, 2022
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an atta ...
Continue ReadingJuly 25, 2022
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external e ...
Continue ReadingJuly 25, 2022
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.Read More ...
Continue ReadingJuly 25, 2022
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volume ...
Continue ReadingJuly 25, 2022
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.Read More ...
Continue ReadingJuly 25, 2022
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.Read More ...
Continue ReadingJuly 25, 2022
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.Read More ...
Continue ReadingJuly 25, 2022
Back to Main