761
|
9.8 |
CRITICAL
Network
apache
|
linkis
|
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of Linkis to versi…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2023-27602
|
2024-10-23 01:35 |
2023-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
762
|
7.5 |
HIGH
Network
apache
|
apache-airflow-providers-apache-spark
|
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects Apache Airflow Spark Provider: before 4.0.1.
Update
|
CWE-20
Improper Input Validation
|
CVE-2023-28710
|
2024-10-23 01:35 |
2023-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
763
|
9.8 |
CRITICAL
Network
apache
|
airflow_hive_provider
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
Update
|
CWE-94
Code Injection
|
CVE-2023-28706
|
2024-10-23 01:35 |
2023-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
764
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Update
|
CWE-416
Use After Free
|
CVE-2023-0471
|
2024-10-23 01:35 |
2023-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
765
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.…
Update
|
CWE-416
Use After Free
|
CVE-2022-3842
|
2024-10-23 01:35 |
2023-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
766
|
8.8 |
HIGH
Network
|
google
|
chrome chrome_os linux_and_chrome_os
|
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an o…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2022-2743
|
2024-10-23 01:35 |
2023-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
767
|
5.4 |
MEDIUM
Network
|
newsignature
|
wp_easy_post_types
|
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and inc…
Update
|
CWE-862
Missing Authorization
|
CVE-2024-10078
|
2024-10-23 01:28 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
768
|
5.4 |
MEDIUM
Network
|
ninjateam
|
click_to_chat
|
The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and inclu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10055
|
2024-10-23 01:28 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
769
|
5.4 |
MEDIUM
Network
|
newsignature
|
wp_easy_post_types
|
The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.4.4 due to insufficient input sanitization and output escapi…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10080
|
2024-10-23 01:27 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
770
|
8.8 |
HIGH
Network
|
newsignature
|
wp_easy_post_types
|
The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.4 via deserialization of untrusted input from the 'text' parameter in the 'ajax…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10079
|
2024-10-23 01:27 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|