KEV agrega CVE-2021-3199 — ONLYOFFICE / Docs
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
- cve_id
- CVE-2021-3199
- vendor_product
- ONLYOFFICE / Docs
KEV agrega CVE-2015-5477 — ISC / BIND
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
KEV agrega CVE-2016-3081 — Apache / Struts
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
KEV agrega CVE-2023-22894 — Strapi / Strapi
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
KEV agrega CVE-2015-3306 — ProFTPD / ProFTPD
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.