NA - CVE-2024-0715 - Expression Language Injection vulnerability in...
Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.
NA - CVE-2024-21890 - The Node.js Permission Model does not clarify...
The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For example: ``` --allow-fs-read=/home/node/.ssh/*.pub...
NA - CVE-2024-21891 - Node.js depends on multiple built-in utility...
Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission...
NA - CVE-2024-21892 - On Linux, Node.js ignores certain environment...
On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of...
NA - CVE-2024-21896 - The permission model protects itself against...
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses...
NA - CVE-2024-22019 - A vulnerability in Node.js HTTP servers allows...
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server...
NA - CVE-2023-6764 -
A format string vulnerability in a...
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50...
NA - CVE-2024-1510 - The WP Shortcodes Plugin — Shortcodes Ultimate...
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up to, and including,...
NA - CVE-2024-1559 - The Link Library plugin for WordPress is...
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input...
NA - CVE-2022-45320 - Liferay Portal before 7.4.3.16 and Liferay DXP...
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing...