Skip to content

TechMedia

Header Image
Category

CRITICAL

104 Posts

Featured

Posted byWpmaster
[vm2] vm2 vulnerable to sandbox escape
Posted byWpmaster
[go.etcd.io/etcd/v3] Etcd-io Improper Authentication vulnerability
Posted byWpmaster
[github.com/sjqzhang/go-fastdfs] sjqzhang go-fastdfs vulnerable to path traversal
Posted byWpmaster
[knplabs/knp-snappy] PHAR deserialization allowing remote code execution

[rdiffweb] rdiffweb Improper Access Control vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/28/202201/10/2023

Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-4724
https://github.com/ikus060/rdiffweb/commit/c4a19cf67d575c4886171b8efcbf4675d51f3929
https://huntr.dev/bounties/e6fb…

[json-pointer] json-pointer vulnerable to Prototype Pollution

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/26/202201/06/2023

A vulnerability, which was classified as critical, has been found in json-pointer. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype …

[flat] flat vulnerable to Prototype Pollution

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/26/202201/06/2023

flat helps flatten/unflatten nested Javascript objects. A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled m…

[topthink/framework] ThinkPHP Framework vulnerable to remote code execution

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/24/202201/04/2023

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands,…

[github.com/sajari/docconv] docconv OS Command Injection vulnerability

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/22/202212/31/2022

A vulnerability was found in docconv prior to version 1.2.1. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The att…

[vm2] vm2 vulnerable to Arbitrary Code Execution

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/21/202201/06/2023

The package vm2 before 3.9.10 is vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
References

http…

[apache-airflow-providers-apache-hive] Apache Airflow Hive Provider vulnerable to Command Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/20/202201/04/2023

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider before 5.0.0.
References

https://nvd.nist.gov/…

[mgallegos/laravel-jqgrid] laravel-jqgrid vulnerable to SQL Injection

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/20/202201/07/2023

A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The…

[github.com/alist-org/alist/v3] Alist vulnerable to Path Traversal

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/16/202212/21/2022

In versions of Alist prior to 3.6.0, a user with only file upload permission can bypass the base path restriction by using ‘… /’ to bypass the base path restriction and upload files to an arbitrary path.
References

https://nvd.nist.gov/vuln/detail/C…

[rfc6902] npm package rfc6902 vulnerable to Prototype Pollution

  • Posted inCRITICAL
  • Posted byWpmaster
  • 12/16/202212/21/2022

A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The e…

Posts navigation

Previous Posts 1 … 3 4 5 6 7 … 11 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close