Skip to content

トピトピニュース

Header Image
Category

HIGH

381 Posts

Featured

Posted byGitHub
[phpxmlrpc/phpxmlrpc] code injection in phpxmlrpc/phpxmlrpc
Posted byGitHub
[ghost] ghost vulnerable to unauthorized newsletter modification via improper access controls
Posted byGitHub
[microweber/microweber] Account Takeover Through Password Reset Poisoning
Posted byGitHub
[apache-airflow] OS Command Injection in Apache Airflow

[org.apache.xmlgraphics:batik] Apache XML Graphics Batik vulnerable to code execution via SVG.

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202211/01/2022

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
References

https://nvd.nist.gov/vuln/detail/C…

[org.apache.xmlgraphics:batik] Untrusted code execution in Apache XML Graphics Batik

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202211/01/2022

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
References

https://nvd.nist….

[Microsoft.NETCore.App.Runtime.linux-musl-arm] .NET Core Elevation of Privilege Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 10/26/202210/26/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial…

[Microsoft.AspNetCore.App.Runtime.osx-arm64] .NET Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 10/22/202210/22/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability…

[thorsten/phpmyfaq] phpMyFAQ vulnerable to Cross-site Scripting

  • Posted inHIGH
  • Posted byGitHub
  • 10/20/202210/21/2022

phpMyFAQ versions 3.1.7 and prior are vulnerable to stored cross-site scripting (XSS). A patch is available on the main branch of the repository and anticipated to be part of version 3.2.0-alpha.
References

https://nvd.nist.gov/vuln/detail/CVE-2022-36…

[org.jenkins-ci.plugins:script-security] Jenkins Script Security Plugin sandbox bypass vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 10/20/202210/21/2022

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, includ…

[org.jenkins-ci.plugins.workflow:workflow-cps] Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution

  • Posted inHIGH
  • Posted byGitHub
  • 10/20/202210/20/2022

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, includi…

[org.jenkins-ci.plugins:katalon] Jenkins Katalon Plugin vulnerable to Protection Mechanism Failure

  • Posted inHIGH
  • Posted byGitHub
  • 10/20/202210/20/2022

Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Katalon with configurable arguments, allowing attackers able to control agent processes to invoke Katalon …

[electron-markdownify] Markdownify subject to Remote Code Execution via malicious markdown file

  • Posted inHIGH
  • Posted byGitHub
  • 10/20/202210/26/2022

Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the “nodeIntegration” option enabled. …

[Microsoft.NETCore.App.Runtime.Mono.tvossimulator-arm64] .NET Remote Code Execution Vulnerability

  • Posted inHIGH
  • Posted byGitHub
  • 10/19/202210/19/2022

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0, and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabilit…

Posts navigation

Previous Posts 1 … 5 6 7 8 9 … 39 Next Posts
トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close