Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
358,413 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and...Show more |
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. |
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI. |
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as dem...Show more |
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled. |
2Webkitgtk Wpewebkit2Webkitgtk Wpe WebkitJun 17, 2026 Apr 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This iss...Show more |
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. |
7Canonical DebianFedoraproject+4 more22Active Iq Unified Manager Cloud BackupDebian Linux+19 moreJun 17, 2026 Apr 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more |
2Fedoraproject Gradle2Fedora GradleJun 17, 2026 Apr 10, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a...Show more |
GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Documents" area. This vulnerability is related to "uploadDocFile.aspx". |
2Fedoraproject Freedesktop2Fedora PopplerJun 17, 2026 Apr 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. |
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS. |
2Libsixel Project Saitoha2Libsixel LibsixelJun 17, 2026 Apr 8, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion. |
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. |
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change. |
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. |
The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, and Windows), do not prevent spoofing of the camera server. An attacker can create a fake camera ser...Show more |
3Debian GraphicsmagickOpensuse3Debian Linux GraphicsmagickLeapJun 17, 2026 Apr 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file. |
3Debian GraphicsmagickOpensuse3Debian Linux GraphicsmagickLeapJun 17, 2026 Apr 8, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 8, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 8, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image...Show more |
3Debian GraphicsmagickOpensuse3Debian Linux GraphicsmagickLeapJun 17, 2026 Apr 8, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE...Show more |
2Graphicsmagick Opensuse2Graphicsmagick LeapJun 17, 2026 Apr 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possib...Show more |
In Materialize through 1.0.0, XSS is possible via the Toast feature. |
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature. |