Search CVE reports
331 – 340 of 40129 results
Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server...
1 affected package
adminer
| Package | 26.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker...
1 affected package
adminer
| Package | 26.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php...
1 affected package
adminer
| Package | 26.04 LTS |
|---|---|
| adminer | Needs evaluation |
Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute...
1 affected package
adminer
| Package | 26.04 LTS |
|---|---|
| adminer | Needs evaluation |
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id`...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field,...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |