CVE-2023-1944
This vulnerability enables ssh access to minikube container using a default password.
Source: CVE-2023-1944
CVE-2023-1944
This vulnerability enables ssh access to minikube container using a default password.
Source: CVE-2023-1944
CVE-2023-25028
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in chuyencode CC Custom Taxonomy plugin <=Â 1.0.1 versions.
Source: CVE-2023-25028
CVE-2022-47448
Cross-Site Request Forgery (CSRF) vulnerability in dev.Xiligroup.Com – MS plugin <=Â 1.12.03 versions.
Source: CVE-2022-47448
CVE-2023-1174
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.
Source: CVE-2023-1174
CVE-2023-33949
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don’t control. The portal property `company.security.strangers.verify` should be set to true.
Source: CVE-2023-33949
CVE-2021-25748
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Source: CVE-2021-25748
CVE-2021-25749
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
Source: CVE-2021-25749
CVE-2023-33948
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
Source: CVE-2023-33948
CVE-2022-46816
Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <=Â 1.1.4 versions.
Source: CVE-2022-46816
CVE-2022-45364
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
Source: CVE-2022-45364