npm libpq是美国npm公司的一个节点本机绑定到 PostgreSQL libpq C 客户端库。 libpq 1.7.1之前的版本存在后置链接漏洞,该漏洞源于Read() 调用 (g *GitArtifactReader).readFromRepository() 打开并读取包含触发器资源定义的文件时不会对此文件进行检查,攻击者利用该漏洞可以读取系统上任何位置的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | github.com/argoproj/argo-events/sensors/artifacts | unspecified ~ 1.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25852 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-22138 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21213 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-25345 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-33915 | 7.0 HIGH | Amazon AWS 竞争条件问题漏洞 |
| CVE-2022-25871 | 5.9 MEDIUM | Prototype Pollution |
| CVE-2022-25872 | 5.3 MEDIUM | Out-of-bounds Read |
| CVE-2019-12354 | ZZCMS SQL注入漏洞 | |
| CVE-2022-33912 | CheckMK Raw Edition 安全漏洞 | |
| CVE-2019-12355 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12356 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12357 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12358 | ZZCMS SQL注入漏洞 | |
| CVE-2019-12359 | ZZCMS SQL注入漏洞 | |
| CVE-2021-45026 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 跨站脚本漏洞 | |
| CVE-2021-45025 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 安全漏洞 | |
| CVE-2021-45024 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 代码问题漏洞 | |
| CVE-2022-31784 | Mitel MiVoice Business Express 安全漏洞 | |
| CVE-2022-32276 | Grafana 授权问题漏洞 | |
| CVE-2021-41490 | OMPL 安全漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet