Vulnerability Repository
A centralized database of discovered vulnerabilities, security advisories, and coordinated disclosures across various software ecosystems.
Horilla - Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
Horilla - Unauthorized Document Overwrite via File Upload Endpoint
Horilla - Insecure Direct Object Reference at /employee/view-file/<int:id>
YesWiki - Persistant Blind XSS at "/?BazaR&vue=consulter"
Intermesh GroupOffice - Reflected XSS in Look and feel section of the application
Intermesh GroupOffice - Blind XSS using user's First and Last names field executed on Synchronization's Address books
Intermesh GroupOffice - Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
Intermesh GroupOffice - DOM-Based XSS in all Date Input Fields Allow Arbitrary JavaScript Execution
Intermesh GroupOffice - Stored XSS in Tasks Comment Section
VLC Media Player - Vulnerability report pending disclosure
Privilege escalation vulnerability in Linux kernel's memory management subsystem.
| CVE ID | Description | Severity | Reference |
|---|---|---|---|
|
|
Horilla - Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation | HIGH | open_in_new Advisory |
|
|
Horilla - Unauthorized Document Overwrite via File Upload Endpoint | HIGH | open_in_new Advisory |
|
|
Horilla - Insecure Direct Object Reference at /employee/view-file/<int:id> | HIGH | open_in_new Advisory |
|
YesWiki - Persistant Blind XSS at "/?BazaR&vue=consulter" | CRITICAL | open_in_new Advisory |
|
|
Intermesh GroupOffice - Reflected XSS in Look and feel section of the application | MEDIUM | open_in_new Advisory |
|
|
Intermesh GroupOffice - Blind XSS using user's First and Last names field executed on Synchronization's Address books | HIGH | open_in_new Advisory |
|
|
Intermesh GroupOffice - Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions | CRITICAL | open_in_new Advisory |
|
|
Intermesh GroupOffice - DOM-Based XSS in all Date Input Fields Allow Arbitrary JavaScript Execution | CRITICAL | open_in_new Advisory |
|
|
Intermesh GroupOffice - Stored XSS in Tasks Comment Section | MEDIUM | open_in_new Advisory |
|
|
NASA - Vulnerability report pending disclosure | MEDIUM | open_in_new Advisory |
|
|
VLC Media Player - Vulnerability report pending disclosure | MEDIUM | open_in_new Advisory |
|
CV
CVE-2023-XXXX
|
Privilege escalation vulnerability in Linux kernel's memory management subsystem. | CRITICAL | open_in_new Advisory |