Page 417 of 8785 results (0.022 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request. • https://github.com/y1s3m0/vulnfind/blob/main/rukovoditel/rce_ajax_request.md • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/experiment.py. The manipulation of the argument mode leads to improper neutralization of special elements used in a template engine. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.1 is able to address this issue. • https://github.com/NYUCCL/psiTurk/commit/47787e15cecd66f2aa87687bf852ae0194a4335f https://github.com/NYUCCL/psiTurk/pull/517 https://github.com/NYUCCL/psiTurk/releases/tag/v3.2.1 https://vuldb.com/?ctiid.219676 https://vuldb.com/?id.219676 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. • https://support.hp.com/us-en/document/ish_7334353-7334378-16 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. • https://support.hp.com/us-en/document/ish_7334353-7334378-16 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. • https://support.hp.com/us-en/document/ish_7334353-7334378-16 •