Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2023
A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221732.
CVSS Score
7.3
EPSS Score
0.001
Published
2023-02-24
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVSS Score
6.1
EPSS Score
0.004
Published
2023-02-24
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-02-24
Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-02-24
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
CVSS Score
7.5
EPSS Score
0.001
Published
2023-02-24
Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.
CVSS Score
4.6
EPSS Score
0.002
Published
2023-02-24
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.
CVSS Score
7.8
EPSS Score
0.002
Published
2023-02-24
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-02-24
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-24
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
CVSS Score
8.1
EPSS Score
0.007
Published
2023-02-24


Contact Us

Shodan ® - All rights reserved