Search CVE reports
1321 – 1330 of 56918 results
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
1 affected package
zabbix
| Package | 16.04 LTS |
|---|---|
| zabbix | Needs evaluation |
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
1 affected package
zabbix
| Package | 16.04 LTS |
|---|---|
| zabbix | Needs evaluation |
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation...
1 affected package
zabbix
| Package | 16.04 LTS |
|---|---|
| zabbix | Needs evaluation |
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
1 affected package
zabbix
| Package | 16.04 LTS |
|---|---|
| zabbix | Needs evaluation |
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
1 affected package
zabbix
| Package | 16.04 LTS |
|---|---|
| zabbix | Needs evaluation |
[Unknown description]
1 affected package
open-iscsi
| Package | 16.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
[Unknown description]
1 affected package
open-iscsi
| Package | 16.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call...
1 affected package
grafana
| Package | 16.04 LTS |
|---|---|
| grafana | Needs evaluation |
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the...
1 affected package
wordpress
| Package | 16.04 LTS |
|---|---|
| wordpress | Needs evaluation |
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized...
1 affected package
freecad
| Package | 16.04 LTS |
|---|---|
| freecad | Needs evaluation |