| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service. |
| The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database. |
| Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. |
| Improper Authorization in GitHub repository usememos/memos prior to 0.9.1. |
| Infoblox NIOS through 8.6.4 has Improper Access Control for Grids. |
| Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. |
| Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. |
| Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
|
| Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file. The attack can be initiated remotely. The name of the patch is b8cb29b43dc704708d598c60ac1881db7cf8e9c3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216988. |
| Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. |
| Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. |
| Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. |
| Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1. |
| ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. |
| ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file path and allows the attacker to perform arbitrary system operation and disrupt of service. |
| Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files. |