| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. |
| Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. |
| Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. |
| Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS). |
| A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. |
| A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. |
| SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component. |
| go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. |
| DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php. |
| APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. |
| Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter. |
| A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution. |
| Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
| Electra Central AC unit – The unit opens an AP with an easily calculated password. |
| Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
| The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |