NA - CVE-2022-45447 - M4 PDF plugin for Prestashop sites, in its...
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerability. The “f” parameter is not properly checked in the resource /m4pdf/pdf.php,...
NA - CVE-2023-34047 - A batch loader function in Spring for GraphQL...
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An...
NA - CVE-2023-4853 - A flaw was found in Quarkus where HTTP security...
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This...
NA - CVE-2023-5042 - Sensitive information disclosure due to...
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713.
NA - CVE-2022-45448 - M4 PDF plugin for Prestashop sites, in its...
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically...
NA - CVE-2023-0829 - Plesk 17.0 through 18.0.31 version, is...
Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an...
High - CVE-2023-3341 - The code that processes control channel...
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size;...
NA - CVE-2023-43477 - The ping_from parameter of ping_tracerte.cgi in...
The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system...
High - CVE-2023-4236 - A flaw in the networking code handling...
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly...