| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the KMS service rendering client-side field level encryption (CSFLE) ineffective. This issue was discovered during internal testing and affects mongodb-client-encryption module version 1.2.0, which was available from 2021-Jan-29 and deprecated in the NPM Registry on 2021-Feb-04. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services from applications residing inside the AWS, GCP, and Azure nework fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption. This issue affect MongoDB Node.js Driver mongodb-client-encryption module version 1.2.0 |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
| A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
| A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
| A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. |
| HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution. |
| Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
| A flaw was found in Hibernate ORM. This vulnerability allows an authenticated attacker to inject arbitrary SQL commands into the underlying database by manipulating the JSON path argument. The issue arises from improper handling of JSON path segments in the JsonPathHelper.appendInlinedJsonPathIncludingPassingClause() method, specifically when using Oracle, DB2, or HANA database dialects. Successful exploitation can lead to authorization bypass and significant data exfiltration, enabling the attacker to access sensitive information from the database. |
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. |
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. |
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. |
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. |
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. |
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. |
| Administrator SQL Injection in Newsletters <= 4.18 versions. |
| Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. |