Lucene search

K

Handsome Testimonials & Reviews Project Security Vulnerabilities

nvd
nvd

CVE-2023-6491

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and.....

4.3CVSS

0.0004EPSS

2024-06-07 06:15 AM
1
osv
osv

CVE-2023-28636

GLPI is a free asset and IT management software package. Starting in version 0.60 and prior to versions 9.5.13 and 10.0.7, a vulnerability allows an administrator to create a malicious external link. This issue is fixed in versions 9.5.13 and...

4.8CVSS

6.8AI Score

0.001EPSS

2023-04-05 06:15 PM
9
vulnrichment
vulnrichment

CVE-2022-0551 Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian...

6.3CVSS

7.2AI Score

0.001EPSS

2022-03-24 02:15 PM
1
osv
osv

BIT-gitlab-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via...

6.8CVSS

6.3AI Score

0.0005EPSS

2024-06-28 07:19 AM
5
githubexploit
githubexploit

Exploit for Heap-based Buffer Overflow in Fortinet Fortiproxy

Usage: python3 cve-2022-42475.py rhost rport lhost 'command'...

9.8CVSS

10AI Score

0.135EPSS

2023-06-16 03:25 AM
24
osv
osv

CVE-2021-36782

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher...

9.9CVSS

6.3AI Score

0.066EPSS

2022-09-07 09:15 AM
6
osv
osv

CVE-2023-28639

GLPI is a free asset and IT management software package. Starting in version 0.85 and prior to versions 9.5.13 and 10.0.7, a malicious link can be crafted by an unauthenticated user. It will be able to exploit a reflected XSS in case any authenticated user opens the crafted link. This issue is...

6.1CVSS

5.9AI Score

0.001EPSS

2023-04-05 06:15 PM
4
osv
osv

CVE-2023-28632

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can modify emails of any user, and can therefore takeover another user account through the "forgotten password" feature. By modifying emails, the user...

8.1CVSS

6.8AI Score

0.001EPSS

2023-04-05 03:15 PM
5
osv
osv

BIT-gitlab-2024-6323

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public...

7.5CVSS

6.3AI Score

0.001EPSS

2024-06-28 07:18 AM
6
osv
osv

BIT-gitlab-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to...

4.3CVSS

6.3AI Score

0.0004EPSS

2024-06-28 07:22 AM
94
aix
aix

AIX is affected by information disclosure due to Python (CVE-2024-28757)

IBM SECURITY ADVISORY First Issued: Thu Jun 13 15:37:38 CDT 2024 The most recent version of this document is available here: https://aix.software.ibm.com/aix/efixes/security/python_advisory9.asc Security Bulletin: AIX is affected by information disclosure due to Python (CVE-2024-28757)...

7.3AI Score

0.0004EPSS

2024-06-13 03:37 PM
4
osv
osv

Malicious code in xterm-addon-clipboard (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (5cf6d3796e2698ca788f0833376dcbd11460b764506f5ffb63bdd8e71262113e) The OpenSSF Package Analysis project identified 'xterm-addon-clipboard' @ 6.0.7 (npm) as malicious. It is considered malicious because: The...

7.4AI Score

2023-11-04 03:38 AM
3
osv
osv

Malicious code in webpack-dev-server.legacy (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (85cd0dbb01e0045658eb423c4580a09f07f36ce5af1689227f99e72348cda4a6) The OpenSSF Package Analysis project identified 'webpack-dev-server.legacy' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The...

7.1AI Score

2023-05-01 11:42 PM
3
osv
osv

Malicious code in gql2ts-from-schema (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (7a1acee750c796d45e602f027ea638a05590a78bb142aca903bfb2bb169466a6) The OpenSSF Package Analysis project identified 'gql2ts-from-schema' @ 2.1.1 (npm) as malicious. It is considered malicious because: - The package.....

7.1AI Score

2023-05-11 06:04 AM
4
osv
osv

Malicious code in virgil-spring-boot-starter (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (1d7b81762635da58744d7567d3ac4b1bf12da5d3c72070a9d2260d40463fcdbb) The OpenSSF Package Analysis project identified 'virgil-spring-boot-starter' @ 20.0.0 (npm) as malicious. It is considered malicious because: - The....

7.1AI Score

2023-05-03 01:30 AM
7
osv
osv

Malicious code in @amops/fetch (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (d9eb323a3c294832e925d2ed472560ab37507fc32711add225d99db97b08bc74) The OpenSSF Package Analysis project identified '@amops/fetch' @ 1.4.1 (npm) as malicious. It is considered malicious because: The package...

7.1AI Score

2024-06-23 02:28 PM
3
osv
osv

Malicious code in smart-commons (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (3d5cef67a87cd4a497f6879379a3829535212f7d703197ce6d3130dd03fd2da6) The OpenSSF Package Analysis project identified 'smart-commons' @ 19.6.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-30 10:44 PM
3
osv
osv

Malicious code in plain-function (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (2e38d4006afc6d5a3ce531ced341af81b57134a68230e68e52122825f587260e) The OpenSSF Package Analysis project identified 'plain-function' @ 20.1.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 10:31 AM
4
osv
osv

Malicious code in links-3 (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (870f8306aa2e95828fa2fdd771044248f7d5e8e715304b6818773620e5c7a1b2) The OpenSSF Package Analysis project identified 'links-3' @ 9.0.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-28 03:50 PM
2
osv
osv

Malicious code in spamsynonym (PyPI)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (bbc650ef44d412610406a674ac1fce3dcb717b01d175614f158016f47b53b1ce) The OpenSSF Package Analysis project identified 'spamsynonym' @ 1.1.1 (pypi) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-05-10 11:43 AM
6
osv
osv

Malicious code in com.unity.xrtools.spatial-hash (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (efa5d123e10b0da3ed7e7898101f41654aa13a572def7acb40b838e0ef88e74b) The OpenSSF Package Analysis project identified 'com.unity.xrtools.spatial-hash' @ 2.0.0 (npm) as malicious. It is considered malicious because: -.....

7.1AI Score

2023-05-08 10:57 AM
5
debiancve
debiancve

CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via...

6.8CVSS

6.6AI Score

0.0005EPSS

2024-06-27 12:15 AM
3
osv
osv

CVE-2023-28838

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell on the server....

9.6CVSS

8.2AI Score

0.001EPSS

2023-04-05 06:15 PM
3
osv
osv

Malicious code in zsbpwebsdktest3 (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a25d6ab5c8c52c4020f38d78237f6c953a826c3e8abc287370befada0727c50a) The OpenSSF Package Analysis project identified 'zsbpwebsdktest3' @ 9999.9.9 (npm) as malicious. It is considered malicious because: - The package.....

7.1AI Score

2023-05-01 09:56 AM
5
osv
osv

Malicious code in seafoam-desktop (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (11b7b515412cb320d382cffb4a3abe4fa232556d7db6ac3dde904bd295b279a3) The OpenSSF Package Analysis project identified 'seafoam-desktop' @ 10.0.0 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-05-09 05:33 AM
9
osv
osv

Malicious code in twinmotion (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (0627a5bcf9887521a72abc5568ab4cf60f65b073d5b0b1c5d2978eeb30079cfd) The OpenSSF Package Analysis project identified 'twinmotion' @ 99.1.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 10:30 AM
9
osv
osv

Malicious code in testforconfusion (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (0463d945d1cd3398ce2594034fd52775ac94fe411f1cc645f88f757522abfc1b) The OpenSSF Package Analysis project identified 'testforconfusion' @ 1.1.0 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 03:50 AM
osv
osv

Malicious code in egstore-carousel (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (e32b3c589f221c9b4e1d86be2924f6e215e6bf6c03844a5084fb1f04eb33275e) The OpenSSF Package Analysis project identified 'egstore-carousel' @ 99.2.2 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 10:32 AM
3
osv
osv

Malicious code in dist-web (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (ff355bd5f2422ce630aeb0652869d4bdaa8f3f18cf576fc60a76588f3acf36b4) The OpenSSF Package Analysis project identified 'dist-web' @ 99.1.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 10:31 AM
2
osv
osv

Malicious code in compositionupdate (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (609e73b696d2a84c8c2169afde78694231815b46be300710ddf913fed7c63d1b) The OpenSSF Package Analysis project identified 'compositionupdate' @ 88.8.8 (npm) as malicious. It is considered malicious because: - The package.....

7.1AI Score

2023-05-01 04:52 AM
4
osv
osv

Malicious code in diesel-site (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (bb78d01ad7ff8d210d59657017d35725abab41a1e59657ff43ac4ac0889ac493) The OpenSSF Package Analysis project identified 'diesel-site' @ 99.9.1 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 10:29 AM
6
osv
osv

Malicious code in apache2 (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (12b1a6eed914c86f199b052822217042e2afa047d6b1d9921fd30b56f1e5e650) The OpenSSF Package Analysis project identified 'apache2' @ 1.1.9 (npm) as malicious. It is considered malicious because: - The package...

7.1AI Score

2023-04-29 04:39 PM
5
osv
osv

Malicious code in bistrosk (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (275abca8527ba6a0a29bf30537bad45fb01533a199b59ca9543da88dda4f8334) The OpenSSF Package Analysis project identified 'bistrosk' @ 200.0.3 (npm) as malicious. It is considered malicious because: The package...

7.2AI Score

2023-11-02 12:58 PM
12
debiancve
debiancve

CVE-2024-4011

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to...

4.3CVSS

6.6AI Score

0.0004EPSS

2024-06-27 12:15 AM
1
osv
osv

Malicious code in @wdp-gov/lineage-component (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (d71a3c3672d613586050e5166426a68d0f5b4ab173d202c331b0259a3919c5a3) The OpenSSF Package Analysis project identified '@wdp-gov/lineage-component' @ 1.0.33 (npm) as malicious. It is considered malicious because: The...

7.1AI Score

2024-06-26 12:41 PM
3
osv
osv

CVE-2023-3413

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to...

7.5CVSS

6.8AI Score

0.001EPSS

2023-09-29 09:15 AM
1
osv
osv

Malicious code in test-test-test-leys-check (PyPI)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a0f1b447a06ae8cd034c08db769374bbc319460cc98a553bfc472d87ca1ef6cc) The OpenSSF Package Analysis project identified 'test-test-test-leys-check' @ 9.9.9 (pypi) as malicious. It is considered malicious because: - The.....

7.1AI Score

2023-05-09 03:32 PM
3
osv
osv

Malicious code in eslint-plugin-indeed (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (cd3cf0dfdda3ea0bf705d385efb05c56b971a408c4a0dceef3771d2e474a33e0) The OpenSSF Package Analysis project identified 'eslint-plugin-indeed' @ 99.99.9 (npm) as malicious. It is considered malicious because: - The...

7.1AI Score

2023-05-01 02:25 AM
3
osv
osv

Malicious code in fing-react-components (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (4e606602dc2c4b6d0550d90156a68cf31799054412bac90062d266e5bcad3d76) The OpenSSF Package Analysis project identified 'fing-react-components' @ 1.15.0 (npm) as malicious. It is considered malicious because: The...

7.1AI Score

2024-06-25 07:40 AM
2
osv
osv

Malicious code in pcln-event-dispatcher (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (58d0757d5f390b101d520dbcfa438dc8fdf9197eccea3aae851f57a1cb09eeb3) The OpenSSF Package Analysis project identified 'pcln-event-dispatcher' @ 999999999.99.9 (npm) as malicious. It is considered malicious because: ...

7.1AI Score

2024-03-07 05:24 AM
2
osv
osv

Malicious code in cncf-interactive-landscape (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (8d2b9d2c5124b5a628ea48abf890a34baae186cb6a3844fc2617ad57b21be8d9) The OpenSSF Package Analysis project identified 'cncf-interactive-landscape' @ 1.0.6 (npm) as malicious. It is considered malicious because: The...

6.9AI Score

2023-08-24 05:00 AM
22
osv
osv

Malicious code in @wdp-gov/catalog-serialization-engine (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (279671687dd3fcc407084cb5aeaab3c707cf47164e8b81c3f1665b61ce19dfd9) The OpenSSF Package Analysis project identified '@wdp-gov/catalog-serialization-engine' @ 3.0.195 (npm) as malicious. It is considered malicious...

7.1AI Score

2024-06-26 01:35 PM
1
debiancve
debiancve

CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit...

8.7CVSS

5.7AI Score

0.0004EPSS

2024-06-27 12:15 AM
cvelist
cvelist

CVE-2022-0551 Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian...

6.3CVSS

7.3AI Score

0.001EPSS

2022-03-24 02:15 PM
1
ubuntucve
ubuntucve

CVE-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit...

8.7CVSS

5.8AI Score

0.0004EPSS

2024-07-01 12:00 AM
cvelist
cvelist

CVE-2024-33923 WordPress SP Project & Document Manager plugin <= 4.69 - Broken Access Control vulnerability

Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through...

6.3CVSS

7.2AI Score

0.0004EPSS

2024-05-03 08:24 AM
1
cve
cve

CVE-2024-4858

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to...

5.3CVSS

6.6AI Score

0.001EPSS

2024-05-25 03:15 AM
24
osv
osv

BIT-gitlab-2024-4901

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit...

8.7CVSS

5.4AI Score

0.0004EPSS

2024-06-28 07:20 AM
1
osv
osv

BIT-gitlab-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members...

5.3CVSS

6.4AI Score

0.0005EPSS

2024-06-28 07:25 AM
93
wpvulndb
wpvulndb

Quiz And Survey Master < 9.0.2 - Contributor+ SQLi

Description The plugin is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role PoC 1) You will need a valid nonce for deletion of quiz questions. 2) Sign in....

7.7AI Score

EPSS

2024-06-10 12:00 AM
1
Total number of security vulnerabilities104271