CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Improper Access Control in Packagist librenms/librenms prior to 22.2.0.
Improper Privilege Management in Packagist snipe/snipe-it prior to 5.3.9.
Code Injection in GitHub repository publify/publify prior to 9.2.8.
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized object.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.