| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation.
This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in heartbeat loop.
This issue affects RustDesk Client: through 1.4.8. |
| A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle.
This vulnerability is associated with program files src/hbbs_http/sync.Rs, hbb_common/src/config.Rs and program routines Strategy merge loop in sync.Rs, Config::set_options().
This issue affects RustDesk Client: through 1.4.8. |
| Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions. |
| Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. |
| Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions. |
| Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions. |
| Unauthenticated PHP Object Injection in Behold <= 1.5 versions. |
| Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. |
| Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. |
| Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. |
| DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue. |
| Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions. |
| Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. |
| Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions. |
| Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions. |
| Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. |
| Subscriber Privilege Escalation in Genemy <= 1.6.6 versions. |
| Unauthenticated Local File Inclusion in Snowy <= 1.13 versions. |