Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – ExternalGuidance allows Stored XSS.This issue affects Mediawiki – ExternalGuidance: from master before 1.39. More information...
Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – MultiBoilerplate Extensionmaste allows Stored XSS.This issue affects Mediawiki – MultiBoilerplate Extensionmaste: from master before 1.39....
In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet,...
An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server...
The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future...
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In /upload/admin_area/actions/update_launch.php, the “type” parameter from a POST request is embedded...
Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbitrary commands with root privileges. NOTE: this...
In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: audioreach: fix potential null pointer dereference It is possible that the topology parsing function audioreach_widget_load_module_common() could return NULL or an error pointer....
In the Linux kernel, the following vulnerability has been resolved: media: stm32-csi: Fix dereference before NULL check In ‘stm32_csi_start’, ‘csidev->s_subdev’ is dereferenced directly while assigning a value to the ‘src_pad’. However the same value...
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.