This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...
Continue ReadingJuly 23, 2022
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. ...
Continue ReadingJuly 23, 2022
There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 through 4.4.2 before 4.4.3. Affected versions allow a logged-in user to run appli ...
Continue ReadingJuly 22, 2022
A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when installed via the EXE installer. The uninstaller attempts to load DLLs out of a W ...
Continue ReadingJuly 22, 2022
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.Read More ...
Continue ReadingJuly 22, 2022
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.Read More ...
Continue ReadingJuly 22, 2022
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.Read More ...
Continue ReadingJuly 22, 2022
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.Read More ...
Continue ReadingJuly 22, 2022
Back to Main