Vulnerabilities
23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34965 | SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information. SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2023-27781 | jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c. jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-4523 | A vulnerability, which was classified as problematic, has been found in vexim2. A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-37623 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. NVD description · AI analysis pending | 9.8 | 1% | PoC ×2 |
| — | |
| CVE-2022-37621 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2022-37617 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js. Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js. NVD description · AI analysis pending | 9.8 | 1% | PoC ×2 |
| — | |
| CVE-2022-32325 | JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c. JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2021-37778 | There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution. There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2021-28832 | VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration. VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2020-36204 | An issue was discovered in the im crate through 2020-11-09 for Rust. An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur. NVD description · AI analysis pending | 4.7 | <1% | PoC |
| — | |
| CVE-2020-35284 | Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation occurs on the client side, and the computation details can be easily determined because the product's source code is available. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2020-7753 | All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). NVD description · AI analysis pending | 7.5 | 4% | PoC ×2 |
| — | |
| CVE-2019-19920 | sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805. NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2019-12240 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-7692 | install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in t install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-20614 | public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI. public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2016-10692 | haxeshim haxe shim to deal with coexisting versions. haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server. NVD description · AI analysis pending | 8.1 | 3% |
| — | ||
| CVE-2016-10675 | libsbmlsim is a module that installs linux binaries for libsbmlsim libsbmlsim downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. libsbmlsim is a module that installs linux binaries for libsbmlsim libsbmlsim downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server. NVD description · AI analysis pending | 8.1 | 2% |
| — | ||
| CVE-2016-10596 | imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested tarball with an attacker controlled tarball if the attacker is on the network or positioned in between the user and the remote server. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2018-11416 | jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (applicat jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2018-6644 | SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI. SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2017-10975 | Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-6877 | Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script. Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script. NVD description · AI analysis pending | 6.1 | <1% |
| — |