Tag
Global Domains International version 2.0 suffers from a cross site scripting vulnerability.
FlightPath LMS version 5.0-rc2 suffers from a cross site scripting vulnerability.
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with specific models. The affected models contain expressions of type `rel1 from type1`. This issue has been patched in version 1.3.1.
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
Gusto Recipes Management version 1.5.1 suffers from an ignored default credential vulnerability.
Groupoffice version 3.4.21 suffers from a directory traversal vulnerability.
Grawlix CMS version 1.1.1 suffers from a cross site scripting vulnerability.
Gravigra CMS version 1.0 suffers from a remote SQL injection vulnerability.