dawid-czarnecki/public-vulnerabilities

dawid-czarnecki/public-vulnerabilities

Releases0
Stars6
[Deprecated] Repositories with publicly disclosed vulnerabilities that I found

CVE History

CVEPublishedCVSS v3CVSS v2
4.7 MEDIUM4.3 MEDIUM

KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.

2.9 LOW2.1 LOW

KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.

9.9 CRITICAL6.5 MEDIUM

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

6.1 MEDIUM4.3 MEDIUM

IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.

9.8 CRITICAL7.5 HIGH

IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

5.3 MEDIUM5 MEDIUM

IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.