Vulnerabilities
17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-35355 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-28686 | Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2021-33896 | Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators. Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators. NVD description · AI analysis pending | 5.3 | 2% |
| — | ||
| CVE-2019-16236 | Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — |