CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
Arrows_nx_f05-f_firmware, Arrows_nx_f05-f, Gp7000f_firmware, Gp7000f, Primepower_firmware, Primepower, Gps_firmware, Gps, Sparc_enterprise_m3000_firmware, Sparc_enterprise_m3000
2022-06-17
N/A
7.8 HIGH
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
