Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Adveris CMS 3.0 Cross Site Scripting

Adveris CMS version 3.0 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox
Advanced HRM 1.6 Insecure Direct Object Reference

Advanced HRM version 1.6 allows for the reseting of the administrative password.

ADMINA BULGARIA Ltd 1.0 Insecure Settings

ADMINA BULGARIA Ltd version 1.0 appears to leave default credentials installed after installation.

Active Super Shop 1.5.1 HTML Injection

Active Super Shop version 1.5.1 suffers from an html injection vulnerability.

Aathesh Soft CMS 0.3.0 Cross Site Scripting

Aathesh Soft CMS version 0.3.0 suffers from a cross site scripting vulnerability.

Ariadna CMS 0.3 Cross Site Scripting

Ariadna CMS version 0.3 suffers from a cross site scripting vulnerability.

CVE-2023-25517: NVIDIA Support

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.

CVE-2023-25523: NVIDIA Support

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the nvdisasm binary file, where an attacker may cause a NULL pointer dereference by providing a user with a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

TP-Link TL-WR940N 4 Buffer Overflow

TP-Link TL-WR940N version 4 suffers from a buffer overflow vulnerability.

CVE-2023-36222: bbs-go 存储式跨站脚本漏洞1 · Issue #206 · mlogclub/bbs-go

Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.