CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution.
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
3500, 3500_firmware, 3500_yl, 3500_yl_firmware, 3par_os, 3par_service_provider, 3par_storeserv_10400, 3par_storeserv_10800, 3par_storeserv_20000, 3par_storeserv_7200c
2022-09-23
N/A
8.8 HIGH
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.
The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7. This is due to missing nonce validation in the ~/includes/settings.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
3500, 3500_firmware, 3500_yl, 3500_yl_firmware, 3par_os, 3par_service_provider, 3par_storeserv_10400, 3par_storeserv_10800, 3par_storeserv_20000, 3par_storeserv_7200c
2022-09-23
N/A
8.8 HIGH
A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.
3500, 3500_firmware, 3500_yl, 3500_yl_firmware, 3par_os, 3par_service_provider, 3par_storeserv_10400, 3par_storeserv_10800, 3par_storeserv_20000, 3par_storeserv_7200c
2022-09-23
N/A
7.8 HIGH
An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.
