Sourcecodester - simple_and_beautiful_shopping_cart_systemĪ vulnerability, which was classified as critical, has been found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Computer Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering Software: before 23.04.06. The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.Įskom_computer - water_metering_software The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module. An app may be able to execute arbitrary code with kernel privileges The identifier VDB-225353 was assigned to this vulnerability.Ī memory corruption issue was addressed with improved state management. It is recommended to upgrade the affected component. Upgrading to version 1.5.11 is able to address this issue. This issue affects some unknown processing of the file classes/dynwid_class.php. VDB-225350 is the identifier assigned to this vulnerability.Ī vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10. Upgrading to version 1.8 is able to address this issue. The manipulation of the argument name leads to sql injection. Affected by this issue is the function hd_add_media/hd_update_media of the file functions.php. Please note that some of the information in the bulletin is compiled from external, open-source reports and is not a direct result of CISA analysis.Īuthentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.Īuthentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.Īll versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.Ī vulnerability was found in HD FLV PLayer Plugin up to 1.7. ![]() ![]() Patch information is provided when available. This information may include identifying information, values, definitions, and related links. Low: vulnerabilities with a CVSS base score of 0.0–3.9Įntries may include additional information provided by organizations and efforts sponsored by CISA.Medium: vulnerabilities with a CVSS base score of 4.0–6.9.High: vulnerabilities with a CVSS base score of 7.0–10.0.The division of high, medium, and low severities correspond to the following scores: Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available. ![]() In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week.
0 Comments
Leave a Reply. |