Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-37243 | The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2023-46865 | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an imag /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image. NVD description · AI analysis pending | 7.2 | 20% | PoC |
| — | |
| CVE-2023-26078 +1 in the same advisory: …26077 | Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-1032 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. NVD description · AI analysis pending | 7.2 | 2% | PoC |
| — | |
| CVE-2022-1033 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-0514 +1 in the same advisory: …0515 | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2022-0372 | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-0203 | Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2022-0242 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2021-4080 | crater is vulnerable to Unrestricted Upload of File with Dangerous Type crater is vulnerable to Unrestricted Upload of File with Dangerous Type NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2018-14925 | Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components. Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components. NVD description · AI analysis pending | 9.8 group max | 2% |
| — |