In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result…
[wp-graphql/wp-graphql] Improper Access Control in wp-graphql
The WPGraphQL WordPress plugin before 0.3.5 doesn’t properly restrict access to information about other users’ roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the…
[craftcms/cms] Improper account password reset in Craft CMS
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account’s password and take over the account by providing a crafted HTTP header to the application while using the password reset fun…
[admesh] Out-of-bounds read in admesh
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
References
https://nvd.nist.gov/vuln/detail/CVE-2018-25033
https://github.com/admesh/admesh/issues…
[k8s.io/ingress-nginx] Improper Input Validation in k8s.io/ingress-nginx
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials o…
[topthink/framework] Deserialization of Untrusted Data in topthink/framework
The package topthink/framework before version 6.0.12 is vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-23592
https://github.com/top-think/fra…
[bignum] Uncaught Exception in bignum
All versions of the npm package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8. When verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
References
h…
[com.twelvemonkeys.imageio:imageio-metadata] External Entity Reference in TwelveMonkeys ImageIO
The package com.twelvemonkeys.imageio:imageio-metadata before version 3.7.1 is vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they ar…
[org.apache.jena:jena] XML External Entity Reference in apache jena
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
References
h…
[yetiforce/yetiforce-crm] Unrestricted Upload of File with Dangerous Type in yetiforce-crm
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the…