Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2023
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
CVSS Score
5.3
EPSS Score
0.007
Published
2023-03-31
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
4.7
EPSS Score
0.0
Published
2023-03-31
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
8.1
EPSS Score
0.001
Published
2023-03-31
Cross-site Scripting in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-03-31
Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
7.2
EPSS Score
0.001
Published
2023-03-31
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
5.5
EPSS Score
0.001
Published
2023-03-31
Improper Neutralization of Input During Web Page Generation in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
4.7
EPSS Score
0.0
Published
2023-03-31
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVSS Score
8.4
EPSS Score
0.001
Published
2023-03-31
A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-224635.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-03-31
A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-03-30


Contact Us

Shodan ® - All rights reserved