Lucene search

K

Handsome Testimonials & Reviews Project Security Vulnerabilities

cve
cve

CVE-2015-10093

A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site scripting. The attack can.....

5.4CVSS

5.2AI Score

0.001EPSS

2023-03-06 07:15 AM
19
osv
osv

Malicious code in dc-test1-asdf (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (04026ef40e4abce9afd70341d1bbb7d8907a917e7a6bd0fd6b7ffb15623a30c0) The OpenSSF Package Analysis project identified 'dc-test1-asdf' @ 1.0.1 (npm) as malicious. It is considered malicious because: The package...

7.3AI Score

2024-06-17 03:46 PM
1
osv
osv

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's...

7.4CVSS

6.7AI Score

0.0004EPSS

2024-04-17 06:24 PM
11
osv
osv

CVE-2022-35953

BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWyrm may be vulnerable to tabnabbing, a form of phishing that gives attackers an opportunity to redirect a user to a malicious site. The issue was...

7.1CVSS

6.6AI Score

0.001EPSS

2022-08-12 09:15 PM
1
githubexploit

10CVSS

9.9AI Score

0.976EPSS

2023-10-06 04:36 AM
200
nuclei
nuclei

GLPI <9.4.6 - Open Redirect

GLPI prior 9.4.6 contains an open redirect vulnerability based on a...

6.1CVSS

6.3AI Score

0.005EPSS

2020-09-04 07:16 AM
11
github
github

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's...

7.4CVSS

6.7AI Score

0.0004EPSS

2024-04-17 06:24 PM
19
osv
osv

Malicious code in mvp-website-html (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (89574af4bb00d4c540ffc8651f5ef4bcc0f72af2368ee6e32346807e91d2e8a0) The OpenSSF Package Analysis project identified 'mvp-website-html' @ 2.0.0 (npm) as malicious. It is considered malicious because: The package...

7.3AI Score

2024-06-18 01:50 PM
1
osv
osv

Malicious code in commando333333 (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (3da17f518475bb94d3d0740d0e1fc486dcce1f4fd1c8f86b9578176c4ea04a03) The OpenSSF Package Analysis project identified 'commando333333' @ 10.0.0 (npm) as malicious. It is considered malicious because: The package...

7.3AI Score

2024-06-17 04:35 PM
github
github

Remote Code Execution (RCE) vulnerability in dropwizard-validation

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. Summary A server-side template injection.....

8.8CVSS

2.2AI Score

0.009EPSS

2020-02-24 05:27 PM
52
osv
osv

CVE-2023-1084

An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted...

2.7CVSS

4.8AI Score

0.001EPSS

2023-03-09 08:15 PM
2
githubexploit
githubexploit

Exploit for Deserialization of Untrusted Data in Apache Log4J

CloudArmor · Runtime Application Self-Protection Module -...

9.1AI Score

2021-12-10 06:42 AM
328
slackware
slackware

[slackware-security] emacs

New emacs packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: patches/packages/emacs-29.4-i586-1_slack15.0.txz: Upgraded. Emacs 29.4 is an emergency bugfix release intended to fix a security vulnerability: ...

7.6AI Score

2024-06-22 08:12 PM
2
osv
osv

Malicious code in requirmeents (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:41 PM
osv
osv

Malicious code in requewsts (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:41 PM
osv
osv

Malicious code in requestr (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:41 PM
osv
osv

Malicious code in reqeist (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:41 PM
osv
osv

Malicious code in py-czrd (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-corxd (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in pycordwd (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in pycordde (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-cordw (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-corf (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-coordd (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-coed (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in py-cod (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:39 PM
osv
osv

Malicious code in pilpow (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:38 PM
osv
osv

Malicious code in pilloa (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:38 PM
osv
osv

Malicious code in pilloo (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:38 PM
osv
osv

Malicious code in pilliw (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:38 PM
osv
osv

Malicious code in customekinter (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:34 PM
osv
osv

Malicious code in colorm (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:34 PM
osv
osv

Malicious code in coloramia (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in coloramka (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in cloroma (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in capmonstercloudcliend (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in capmonstercloudclieent (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in capmonstercloudclent (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in capmonsterccloudclient (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:33 PM
osv
osv

Malicious code in bips-utils (PyPI)

-= Per source details. Do not edit below this...

7.1AI Score

2024-06-25 01:32 PM
githubexploit
githubexploit

Exploit for Untrusted Search Path in Microsoft

Privilege escalation using the XAML diagnostics API...

7.3CVSS

7.3AI Score

0.002EPSS

2024-01-11 07:17 PM
318
cve
cve

CVE-2023-3014

A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. Affected is an unknown function of the file admin/admincore.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the...

6.1CVSS

6AI Score

0.001EPSS

2023-05-31 02:15 PM
18
cve
cve

CVE-2023-31438

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security...

5.3CVSS

5.3AI Score

0.001EPSS

2023-06-13 05:15 PM
14
cve
cve

CVE-2023-2245

A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to....

9.8CVSS

9.5AI Score

0.002EPSS

2023-04-22 05:15 PM
34
cve
cve

CVE-2023-1971

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994 tpAdmin 1.3.12. Affected is the function remote of the file application\admin\controller\Upload.php. The manipulation of the argument url leads to server-side request forgery. It is possible to....

6.3CVSS

5.2AI Score

0.001EPSS

2023-04-10 05:15 PM
31
cve
cve

CVE-2023-1570

A vulnerability, which was classified as problematic, has been found in syoyo tinydng. Affected by this issue is the function __interceptor_memcpy of the file tiny_dng_loader.h. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has.....

5.5CVSS

5.6AI Score

0.001EPSS

2023-03-22 03:15 PM
16
cve
cve

CVE-2023-1303

A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the component System File Management Module. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The....

9.8CVSS

9.4AI Score

0.007EPSS

2023-03-09 10:15 PM
25
cve
cve

CVE-2023-1010

A vulnerability classified as critical was found in vox2png 1.0. Affected by this vulnerability is an unknown functionality of the file vox2png.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.....

5.5CVSS

5.7AI Score

0.0005EPSS

2023-02-24 11:15 AM
22
cve
cve

CVE-2023-0243

A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack...

9.8CVSS

9.7AI Score

0.001EPSS

2023-01-12 03:15 PM
43
cve
cve

CVE-2022-4495

A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue affects the function renderCell of the file src/collective/dms/basecontent/browser/column.py. The manipulation leads to cross site scripting. The attack may be initiated...

6.1CVSS

5.9AI Score

0.001EPSS

2022-12-14 03:15 PM
45
Total number of security vulnerabilities104271