Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-36019

Microsoft Power Platform Connector Spoofing Vulnerability

CVE
#vulnerability#microsoft
CVE-2023-35628

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2018-16153: Opencast News | Apereo

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.

CVE-2022-44543: TYPO3 Security Bulletins

The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.

CVE-2023-26920: report.md

fast-xml-parser before 4.1.2 allows __proto__ for Prototype Pollution.

CVE-2020-10676: Announcements

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

CVE-2023-48227: Backoffice User can bypass "Publish" restriction

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.

CVE-2009-4123: CVE-2009-4123 - GitHub Advisory Database

The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.

CVE-2013-2513: CVE-2013-2513 - GitHub Advisory Database

The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

CVE-2023-6593: Devolutions

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.