CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple pages: hr/subscription.jsp and hr/application.jsp and and hr/index.jsp (with view= and data=).
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
