<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Ant</title>
  <link>https://cvedaily.com/pages/tags/ant.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ant.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Ant</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-60689 – An unauthenticated command injection vulnerability exists in the Start_EPI funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60689</guid>
    <pubDate>Thu, 13 Nov 2025 16:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60689</strong></p>
  <p>An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Succe…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35371 – Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35371</guid>
    <pubDate>Fri, 29 Nov 2024 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35371</strong></p>
  <p>Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47714 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47714</guid>
    <pubDate>Mon, 21 Oct 2024 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47714</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7996: use hweight16 to get correct tx antenna  The chainmask is u16 so using hweight8 cannot get correct tx_ant. Without this patch, the tx_ant of band 2 would be -1 and lead to the following issue: BUG: KASAN: stack-out-of-bounds in mt7996_mcu_add_sta+0x12e0/0x16e0 [mt7996e]</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37779 – WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37779</guid>
    <pubDate>Mon, 23 Sep 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37779</strong></p>
  <p>WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-46983 – sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46983</guid>
    <pubDate>Thu, 19 Sep 2024 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-46983</strong></p>
  <p>sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3488 – File Upload vulnerability in unauthenticated
session found in OpenText™ iManager...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3488</guid>
    <pubDate>Wed, 15 May 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3488</strong></p>
  <p>File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-3462 – Ant Media Server Community Edition in a default configuration is vulnerable to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3462</guid>
    <pubDate>Tue, 14 May 2024 15:41:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-3462</strong></p>
  <p>Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.  All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32656 – Ant Media Server is live streaming engine software. A local privilege escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32656</guid>
    <pubDate>Mon, 22 Apr 2024 23:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32656</strong></p>
  <p>Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with Java Management Extensions (JMX) enabled and authentication disabled on localhost o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23686 – DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23686</guid>
    <pubDate>Fri, 19 Jan 2024 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23686</strong></p>
  <p>DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3653 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3653</guid>
    <pubDate>Tue, 08 Aug 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3653</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS.  This issue affects E-Commerce Software: before 11.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3652 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3652</guid>
    <pubDate>Tue, 08 Aug 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3652</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Reflected XSS.  This issue affects E-Commerce Software: before 11.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3651 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3651</guid>
    <pubDate>Tue, 08 Aug 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3651</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection.  This issue affects E-Commerce Software: before 11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37647 – SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37647</guid>
    <pubDate>Mon, 31 Jul 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37647</strong></p>
  <p>SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23306 – The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23306</guid>
    <pubDate>Tue, 23 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23306</strong></p>
  <p>The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23303 – The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23303</guid>
    <pubDate>Tue, 23 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23303</strong></p>
  <p>The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31741 – There is a command injection vulnerability in the Linksys E2000 router with firm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31741</guid>
    <pubDate>Tue, 23 May 2023 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31741</strong></p>
  <p>There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31742 – There is a command injection vulnerability in the Linksys WRT54GL router with fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31742</guid>
    <pubDate>Mon, 22 May 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31742</strong></p>
  <p>There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31707 – SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31707</guid>
    <pubDate>Fri, 19 May 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31707</strong></p>
  <p>SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22602 – When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a speciall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22602</guid>
    <pubDate>Sat, 14 Jan 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22602</strong></p>
  <p>When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass.  The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot co…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38733 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38733</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38733</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38732 – SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38732</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38732</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38731 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38731</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38731</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38730 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38730</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38730</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38729 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38729</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38729</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38728 – SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38728</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38728</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38737 – SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38737</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38737</strong></p>
  <p>SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38736 – SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38736</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38736</strong></p>
  <p>SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38734 – SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38734</guid>
    <pubDate>Fri, 28 Oct 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38734</strong></p>
  <p>SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2726 – A vulnerability classified as critical has been found in SEMCMS. This affects an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2726</guid>
    <pubDate>Tue, 09 Aug 2022 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2726</strong></p>
  <p>A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205839.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36374 – When reading a specially crafted ZIP archive, or a derived formats, an Apache An...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36374</guid>
    <pubDate>Wed, 14 Jul 2021 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36374</strong></p>
  <p>When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affecte…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36373 – When reading a specially crafted TAR archive an Apache Ant build can be made to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36373</guid>
    <pubDate>Wed, 14 Jul 2021 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36373</strong></p>
  <p>When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11979 – As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of tem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11979</guid>
    <pubDate>Thu, 01 Oct 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11979</strong></p>
  <p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-379</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1945 – Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1945</guid>
    <pubDate>Thu, 14 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1945</strong></p>
  <p>Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18350 – In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18350</guid>
    <pubDate>Wed, 23 Oct 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18350</strong></p>
  <p>In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-17383 – Jenkins through 2.93 allows remote authenticated administrators to conduct XSS a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17383</guid>
    <pubDate>Wed, 06 Dec 2017 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-17383</strong></p>
  <p>Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9810 – There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9810</guid>
    <pubDate>Mon, 17 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9810</strong></p>
  <p>There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2850 – Cross-site scripting (XSS) vulnerability in index-login.ant in the ANTlabs InnGa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2850</guid>
    <pubDate>Tue, 07 Jul 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2850</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in index-login.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2849 – SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2849</guid>
    <pubDate>Tue, 07 Jul 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2849</strong></p>
  <p>SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-1461 – The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1461</guid>
    <pubDate>Wed, 21 Mar 2012 10:11:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-1461</strong></p>
  <p>The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (fo…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-5483 – Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5483</guid>
    <pubDate>Tue, 16 Oct 2007 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-5483</strong></p>
  <p>Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6496 – The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6496</guid>
    <pubDate>Wed, 13 Dec 2006 21:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6496</strong></p>
  <p>The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3223 – Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3223</guid>
    <pubDate>Tue, 27 Jun 2006 21:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3223</strong></p>
  <p>Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP) r8 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the description field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-3126 – The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3126</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-3126</strong></p>
  <p>The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files.</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-2405 – Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Ant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2405</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-2405</strong></p>
  <p>Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2405">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
