Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.Read More ...
Continue ReadingJuly 22, 2022
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.Read More ...
Continue ReadingJuly 22, 2022
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.Read More ...
Continue ReadingJuly 22, 2022
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.Read More ...
Continue ReadingJuly 22, 2022
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.Read More ...
Continue ReadingJuly 22, 2022
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.Read More ...
Continue ReadingJuly 22, 2022
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.Read More ...
Continue ReadingJuly 22, 2022
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.Read More ...
Continue ReadingJuly 22, 2022
Back to Main