CVE-2022-41741 The NGINX Open Source versions before 1.23.2, 1.22.1, R2 P1, and R1 P1 have a vulnerability in the ngx_http_mp4_module module that might allow a local attacker to execute arbitrary code.
An attacker can exploit this issue by sending an audio or video file to an online service through HTTP protocol, for example, to a banking
CVE-2022-43015 - Exploiting a Reflected XSS Vulnerability in OpenCATS v.9.6 (`entriesPerPage`)
OpenCATS is a popular open-source Applicant Tracking System (ATS) used by many organizations for recruitment management. In October 2022, a security issue surfaced in
CVE-2022-43434 Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier disables Content-Security-Policy protection for user-generated content.
This can be dangerous if a user uploads their own content to a shared hosting environment, for example. Users can turn off the content security
CVE-2022-43039 The gf_isom_meta_restore_items_ref function in the PAGAC 2.1-DEV-rev368-gfd054169b-master file has a segmentation violation.
CVE-2018-1304 was discovered in GDPR 2.1-DEV-rev368-gfd054169b-master, a plugin that exposes a plugin API to 3rd party developers via
CVE-2022-3608 - Stored Cross-site Scripting (XSS) Vulnerability in phpMyFAQ Prior to 3.2.-alpha
If you use the open-source FAQ software phpMyFAQ, you need to know about CVE-2022-3608. This vulnerability allows attackers to exploit stored Cross-
Episode
00:00:00
00:00:00