NA - CVE-2023-31417 - Elasticsearch generally filters out sensitive...
Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use...
NA - CVE-2023-31418 - An issue has been identified with how...
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by...
NA - CVE-2023-31419 - A flaw was discovered in Elasticsearch,...
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
NA - CVE-2023-5793 - A vulnerability was found in flusity CMS and...
A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCreateForm of the file /core/tools/customblock.php of the component Dashboard....
NA - CVE-2023-5794 - A vulnerability was found in PHPGurukul Online...
A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The...
NA - CVE-2023-5795 - A vulnerability was found in CodeAstro POS...
A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profil of the component Profile...
NA - CVE-2023-5796 - A vulnerability was found in CodeAstro POS...
A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /setting of the component Logo Handler. The...
NA - CVE-2023-31416 - Secret token configuration is never applied...
Secret token configuration is never applied when using ECK =8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
NA - CVE-2023-0897 -
Sielco PolyEco1000 is vulnerable to a session...
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests.