Security
Headlines
HeadlinesLatestCVEs

Tag

#apache

CVE-2021-33504: Alerts | Couchbase

Couchbase Server before 7.1.0 has Incorrect Access Control.

CVE
#xss#csrf#vulnerability#web#apple#dos#apache#memcached#js#java#kubernetes#rce#perl#ldap#log4j#buffer_overflow#auth#ssl
CVE-2022-31500: Security Advisories | KNIME

In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

CVE-2022-29627: OpenSource/exploit_idor.md at main · nsparker1337/OpenSource

An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.

CVE-2022-29628: OpenSource/exploit_rxss.md at main · nsparker1337/OpenSource

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVE-2022-29659: Responsive Online Blog Website using PHP/MySQL with Source Code

Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

CVE-2022-30470: FileRun - Selfhosted File Manager with Sharing and Backup for Photos, Docs & More

In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

CVE-2022-30034: Multiple Vulnerabilities in Flower and Downstream Attacks on Airflow

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

CVE-2022-30513: School Dormitory Management System in PHP/OOP Free Source Code

School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

Product Show Room Site 1.0 Cross Site Scripting

Product Show Room Site version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

GHSA-qw3f-w4pf-jh5f: Regular expression denial of service in apache tika

We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.