Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-0120

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an unauthorised user.

CVE
#git#auth
CVE-2022-4343

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which a project member can leak credentials stored in site profile.

CVE-2023-24675

Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

CVE-2023-41364: HOME - tine

In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

CVE-2023-24674

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

CVE-2022-44349: CVEs/CVE-2022-44349 at main · MVRC-ITSEC/CVEs

NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-4704: Misconfiguration in message sending function in icms2

External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-4696: huntr – Security Bounties for any GitHub repository

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-4698: huntr – Security Bounties for any GitHub repository

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.