CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page.
500f, 500f_firmware, 7-mode_transition_tool, 8300, 8300_firmware, 8700, 8700_firmware, A220, A220_firmware, A250
2021-06-02
N/A
7.5 HIGH
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
Dir-816_firmware, Dir-816, Dsl-2750u_firmware, Dsl-2750u, Dir-806_firmware, Dir-806, Dcs-930l_firmware, Dcs-930l, Dcs-931l_firmware, Dcs-931l
2020-08-24
N/A
8.8 HIGH
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
