Vulnerabilities
25 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-47832 | ssoready is a single sign on provider implemented via docker. ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits differential behavior between XML parsers. Users of https://ssoready.com, the public hosted instance of SSOReady, are unaffected. We advise folks who self-host SSOReady to upgrade to 7f92a06 or later. Do so by updating your SSOReady Docker images from sha-... to sha-7f92a06. There are no known workarounds for this vulnerability. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2023-47430 | Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_c Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2023-33476 | ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-1971 | The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2022-26505 | A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files. A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files. NVD description · AI analysis pending | 7.4 | 2% |
| — | ||
| CVE-2020-28926 | ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove. NVD description · AI analysis pending | 9.8 | 13% | PoC |
| — | |
| CVE-2020-28371 | An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStream.java has a boundary check to prevent out-of-bounds memory read/write operations. However, an integer overflow leads to bypassing this check and achieving the out-of-bounds access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-17360 +1 in the same advisory: …17361 | An issue was discovered in ReadyTalk Avian 1.2.0. An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are performed to prevent out-of-bounds memory read/write. However, two of these boundary checks contain an integer overflow that leads to a bypass of these checks, and out-of-bounds read/write. NOTE: This vulnerability only affects products that are no longer supported by the maintainer NVD description · AI analysis pending | 7.8 group max | 1% |
| — | ||
| CVE-2019-18659 | The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstr The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are affected by design (e.g., use of Android versus iOS does not matter); testing in an open RF environment is, of course, contraindicated. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2019-9604 +1 in the same advisory: …9605 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions. PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2018-20138 | PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastName, a similar issue to CVE-2018-14541. PHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastName, a similar issue to CVE-2018-14541. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-14541 | PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields. PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-17892 | Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter. Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2017-17649 | Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. NVD description · AI analysis pending | 6.1 | 3% | PoC ×2 |
| — | |
| CVE-2017-17627 | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC ×2 |
| — | |
| CVE-2017-17626 | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2017-15985 | Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2016-5050 | Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .a Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file. NVD description · AI analysis pending | 9.8 group max | 3% |
| — |