CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
2021-11-02
N/A
6.1 MEDIUM
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
