NA - CVE-2023-39677 - MyPrestaModules Prestashop Module v6.2.9 and...
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
NA - CVE-2023-42321 - Cross Site Request Forgery (CSRF) vulnerability...
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.
NA - CVE-2019-19450 - paraparser in ReportLab before 3.5.31 allows...
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '
NA - CVE-2022-1438 - A flaw was found in Keycloak. Under specific...
A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.
NA - CVE-2023-0118 - An arbitrary code execution flaw was found in...
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.
NA - CVE-2023-0462 - An arbitrary code execution flaw was found in...
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
NA - CVE-2023-41902 - An XPC misconfiguration vulnerability in...
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.