Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Global Domains International 2.0 Cross Site Scripting

Global Domains International version 2.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#google#auth#firefox
FlightPath LMS 5.0-rc2 Cross Site Scripting

FlightPath LMS version 5.0-rc2 suffers from a cross site scripting vulnerability.

CVE-2023-40763: Taxi Booking Script | PHPJabbers

User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-40579: OpenFGA Authorization Bypass

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with specific models. The affected models contain expressions of type `rel1 from type1`. This issue has been patched in version 1.3.1.

CVE-2019-13690

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

CVE-2019-13689

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)

Gusto Recipes Management 1.5.1 Insecure Settings

Gusto Recipes Management version 1.5.1 suffers from an ignored default credential vulnerability.

Groupoffice 3.4.21 Directory Traversal

Groupoffice version 3.4.21 suffers from a directory traversal vulnerability.

Grawlix CMS 1.1.1 Cross Site Scripting

Grawlix CMS version 1.1.1 suffers from a cross site scripting vulnerability.

Gravigra CMS 1.0 SQL Injection

Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.