Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2023-28864: Chef Infra Server Release Notes

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVE
#sql#xss#vulnerability#web#ios#mac#windows#apple#amazon#ubuntu#linux#debian#red_hat#dos#apache#redis#nodejs#js#git#java#rce#perl#ldap#nginx#aws#log4j#buffer_overflow#acer#auth#ssh#ruby#rpm#postgres#ssl
CVE-2021-37386: WSTG - Latest | OWASP Foundation

Furukawa 423-41W/AC before v1.1.4 and LD421-21W before v1.3.3 were discovered to contain an HTML injection vulnerability via the serial number update function.

CVE-2023-36656: Escape keys by yurishkuro · Pull Request #15 · mafintosh/json-markup

Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.

Travelable 1.0 Cross Site Scripting

Travelable version 1.0 suffers from a persistent cross site scripting vulnerability.

BloodBank 1.1 Cross Site Scripting

BloodBank version 1.1 suffers from a cross site scripting vulnerability.

Carlisting 1.6 Cross Site Scripting

Carlisting version 1.6 suffers from a cross site scripting vulnerability.

Lawyer CMS 1.6 Cross Site Scripting

Lawyer CMS version 1.6 suffers from a cross site scripting vulnerability.

JobSeeker 1.5 Cross Site Scripting

JobSeeker version 1.5 suffers from a cross site scripting vulnerability.

Ecommerce 1.15 Cross Site Scripting

Ecommerce version 1.15 suffers from a cross site scripting vulnerability.

Insurance 1.2 Cross Site Scripting

Insurance version 1.2 suffers from a cross site scripting vulnerability.