Vulnerabilities
16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-13256 | Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-29566 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2023-22726 | act is a project which allows for local running of github actions. act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The /upload endpoint is vulnerable to path traversal as filepath is user controlled, and ultimately flows into os.Mkdir and os.Open. The /artifact endpoint is vulnerable to path traversal as the path is variable is user controlled, and the specified file is ultimately returned by the server. This has been addressed in version 0.2.40. Users are advised to upgrade. Users unable to upgrade may, during implementation of Open and OpenAtEnd for FS, ensure to use ValidPath() to check against path traversal or clean the user-provided paths manually. NVD description · AI analysis pending | 8.8 | 1% | PoC ×2 |
| — | |
| CVE-2020-28453 | This affects all versions of package npos-tesseract. This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-28446 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2022-1914 | The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in adm The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2021-24403 | The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before insertin The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors NVD description · AI analysis pending | 7.2 | 2% | PoC ×2 |
| — | |
| CVE-2018-18584 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. NVD description · AI analysis pending | 6.5 | 3% |
| — | ||
| CVE-2018-14682 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2018-13771 | The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-13469 | The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to s The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-5983 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2016-10320 | textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. NVD description · AI analysis pending | 7.8 | 2% | PoC |
| — |