NA - CVE-2021-3986 - A vulnerability in janeczku/calibre-web allows...
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name...
NA - CVE-2021-3987 - An improper access control vulnerability exists...
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the...
NA - CVE-2021-3988 - A Cross-site Scripting (XSS) vulnerability...
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover...
NA - CVE-2021-3991 - An Improper Authorization vulnerability exists...
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to...
NA - CVE-2022-1226 - A Cross-Site Scripting (XSS) vulnerability in...
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects...
NA - CVE-2023-0109 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and...
NA - CVE-2023-0737 - wallabag version 2.5.2 contains a Cross-Site...
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in...
NA - CVE-2023-2332 - A stored Cross-site Scripting (XSS)...
A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the...
NA - CVE-2023-4679 - A use after free vulnerability exists in GPAC...
A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a...