Tag: SQLInjection

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No35

    MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…

  • Vulnerability Watch No32

    go-git Symlink Escape Can Reach Files Outside Worktrees • ZenML Artifact Poisoning Enables Remote Code Execution • Absinthe Federation Atom Exhaustion Can Crash Erlang Nodes • ClamAV XAR Parser Memory Corruption Can Trigger DoS • Crafted Mach-O Files Can Crash ClamAV Scanners…

  • Vulnerability Watch No29

    Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…

  • Vulnerability Watch No27

    H3C NX15 Web API Exposes Dangerous Routine • UTT HiPER 1200GW Hit by Remote Buffer Overflow • UTT HiPER 1250GW TempName Overflow Exposed • UTT HiPER 1250GW 5 GHz Endpoint Overflow • ESAFENET CDG KeyID Parameter Enables SQL Injection…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…

  • Vulnerability Watch No23

    Hashi Vault JS Flaw Enables Path and Query Injection • Defaults Deep Library Vulnerable to Prototype Pollution • DSSRF DNS Handling Bug Reopens SSRF Paths • Vault Webhook Flaw Can Leak Kubernetes Service Account Tokens • cPanel Database Rename Flaw Enables Root-Context SQL Execution…

  • Vulnerability Watch No22

    Yggdrasil Package Manager Flaw Enables Root Code Execution • Advantech ECU-1251D Exposes Passwordless Root SSH Access • Joomla Gridbox Admin Interface Hit by Multiple CSRF Flaws • Hospital Management System Report Page Exposed to Critical SQL Injection

  • Vulnerability Watch No21

    Hardcoded Backdoor Exposes WordPress Sites to Admin Takeover • Easy Digital Downloads Upload Flaw Could Enable Code Execution • WooCommerce Wholesale Plugin Lets Authors Become Administrators • Netty OCSP Race Can Leak Data to Revoked Servers • Netty Accepts Replayed Expired OCSP Responses…