Security assessment and information provision

This site provides information on security and offers web audit tools.

  Annoucement          Show List

Update Date":May 19, 2024, 10:37 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date
1 - - - Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request. New - CVE-2024-36050
2024-05-19 07:15 2024-05-19
2 - - - Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages). New - CVE-2024-28064
2024-05-19 07:15 2024-05-19
3 - - - Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS. New - CVE-2024-28063
2024-05-19 07:15 2024-05-19
4 - - - QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values. New - CVE-2024-36048
2024-05-19 06:15 2024-05-19
5 - - - A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has … New CWE-89
SQL Injection
CVE-2024-5094
2024-05-19 05:15 2024-05-19
6 - - - question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property. New - CVE-2024-36043
2024-05-19 05:15 2024-05-19
7 - - - A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The ex… New CWE-89
SQL Injection
CVE-2024-5093
2024-05-19 04:15 2024-05-19
8 - - - aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle atta… New - CVE-2024-34083
2024-05-19 04:15 2024-05-19
9 - - - IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539. New CWE-502
 Deserialization of Untrusted Data
CVE-2024-31879
2024-05-19 01:15 2024-05-19
10 7.8 HIGH
Local
- - MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user. New CWE-863
 Incorrect Authorization
CVE-2024-3745
2024-05-18 22:15 2024-05-18

Update Date:Feb. 5, 2024, 11:32 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date
1 7 重要
Local
Canonical
Linux
Ubuntu
Linux Kernel
Linux の Linux Kernel 等複数ベンダの製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2022-2602 2024-02-5 11:24 2022-10-19
2 7.8 重要
Local
Canonical
Linux
Ubuntu
Linux Kernel
Linux の Linux Kernel 等複数ベンダの製品における二重解放に関する脆弱性 CWE-415
二重解放
CVE-2022-2588 2024-02-5 11:09 2022-08-9
3 7.8 重要
Local
Canonical
Linux
Ubuntu
Linux Kernel
Linux の Linux Kernel 等複数ベンダの製品における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2022-2586 2024-02-5 11:02 2022-08-9
4 5.5 警告
Local
fortanix confidential computing manager fortanix の Intel Software Guard Extensions 用 confidential computing manager における脆弱性 CWE-noinfo
情報不足
CVE-2023-38021 2024-02-2 17:01 2023-12-30
5 5.5 警告
Local
fortanix confidential computing manager fortanix の Intel Software Guard Extensions 用 confidential computing manager における脆弱性 CWE-noinfo
情報不足
CVE-2023-38022 2024-02-2 17:01 2023-12-30
6 5.5 警告
Local
scontain scone scontain の scone における脆弱性 CWE-noinfo
情報不足
CVE-2023-38023 2024-02-2 17:01 2023-12-30
7 7.2 重要
Network
oretnom23 house rental management system oretnom23 の house rental management system における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-0502 2024-02-2 17:01 2024-01-13
8 7.5 重要
Network
newtonsoft json.net newtonsoft の json.net における例外的な状態の処理に関する脆弱性 CWE-755
例外的な状態における不適切な処理
CVE-2024-21907 2024-02-2 17:01 2024-01-3
9 5.5 警告
Local
アップル iPadOS
iOS
複数のアップル製品における脆弱性 CWE-noinfo
情報不足
CVE-2022-46710 2024-02-2 16:58 2022-12-13
10 7.8 重要
Local
- アップルの macOS における脆弱性 CWE-noinfo
情報不足
CVE-2022-46721 2024-02-2 16:58 2022-10-24

Target Period : 2024-05-12 〜 2024-05-19

No Name Genre Version Release date Security Fix Release Information
1 New!! MariaDB 10.4 database 10.4.34 2024-05-16 Unknown Show
2 New!! MariaDB 10.5 database 10.5.25 2024-05-16 Information Yes Show
3 New!! MariaDB 10.6 database 10.6.18 2024-05-16 Information Yes Show
4 New!! UIkit 3 framework 3.20.10 2024-05-13 Unknown Show

Target Period : 2024-04-01 〜 2024-08-31

No Name Normal Support Security Support Extended Support
1 Warning Ubuntu 16.04 LTS 2021-04-30 2024-04-30
2 Warning Django3.2 LTS 2021-12-31 2024-04-30
3 Warning Node.js 16 (LTS) 2022-10-18 2024-04-30
4 Warning MongoDB 4.4 2024-04-30
5 Warning Ubuntu 23.04 2024-04-30
6 Warning Fedora 38 2024-05-14
7 Warning Angular 15 2023-05-18 2024-05-18
8 Linux Kernel 5.18 2024-05-25
9 CentOS 6 2017-03-31 2020-11-30 2024-06-30
10 Red Hat Enterprise Linux 6 2022-05-10 2020-11-30 2024-06-30
11 Red Hat Enterprise Linux 7 2020-08-6 2024-06-30
12 FreeBSD 12 2024-06-30
13 MariaDB 11.0 2024-06-30
14 SQL Server 2014 Service Pack 3 2019-07-9 2024-07-9
15 CentOS 7 2020-12-31 2024-07-30
2024-5-18 JST
media_news
vulnerability_notification_site