Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2023
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
8.0
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
8.8
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
8.0
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
6.0
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
9.3
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVSS Score
3.4
EPSS Score
0.002
Published
2023-03-07
Information disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialized View (IMMV) created by pg_ivm may reflect rows with Row-Level Security that the owner of the IMMV should not have access to. As a result, information in tables protected by Row-Level Security may be retrieved by a user who is not authorized to access it.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-03-07
Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without specifying schema names. Under certain conditions, pg_ivm may be tricked to execute unexpected functions from other schemas with the IMMV owner's privilege. If this vulnerability is exploited, an unexpected function provided by an attacker may be executed with the privilege of the materialized view owner.
CVSS Score
8.8
EPSS Score
0.006
Published
2023-03-07
A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability affects unknown code of the file src/at/hgz/vocabletrainer/VocableTrainerProvider.java. The manipulation leads to path traversal. Attacking locally is a requirement. Upgrading to version 1.3.1 is able to address this issue. The name of the patch is accf6838078f8eb105cfc7865aba5c705fb68426. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-222328.
CVSS Score
5.3
EPSS Score
0.002
Published
2023-03-07
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
7.2
EPSS Score
0.007
Published
2023-03-07


Contact Us

Shodan ® - All rights reserved