<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bootstrap (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/bootstrap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bootstrap-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bootstrap (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32905 – OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32905</guid>
    <pubDate>Fri, 29 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32905</strong></p>
  <p>OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45055 – CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45055</guid>
    <pubDate>Wed, 13 May 2026 21:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45055</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the admin equivalent in Admin::passwordRequest()). An unauthenticated attacker who know…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42222 – Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42222</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42222</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41387 – OpenClaw before 2026.3.22 contains an incomplete host environment variable sanit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41387</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41387</strong></p>
  <p>OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. Attackers can exploit approved exec requests to redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-183</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41386 – OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41386</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41386</strong></p>
  <p>OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40518 – ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40518</guid>
    <pubDate>Fri, 17 Apr 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40518</strong></p>
  <p>ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation and write files outside the intended custom-agent directory, potentially achieving arbitrary fil…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6507 – A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds wr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6507</guid>
    <pubDate>Fri, 17 Apr 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6507</strong></p>
  <p>A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40044 – Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40044</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40044</strong></p>
  <p>Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, which are unserialized during framework bootstrap before authentication checks occur.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31940 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31940</guid>
    <pubDate>Fri, 10 Apr 2026 18:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31940</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5412 – In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5412</guid>
    <pubDate>Fri, 10 Apr 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5412</strong></p>
  <p>In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32987 – OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during dev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32987</guid>
    <pubDate>Sun, 29 Mar 2026 13:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32987</strong></p>
  <p>OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34386 – Fleet is open source device management software. Prior to 4.81.0, a SQL injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34386</guid>
    <pubDate>Fri, 27 Mar 2026 19:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34386</strong></p>
  <p>Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet database, and inject arbitrary content into team configs via direct API calls. Version 4.81.0 patches…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31957 – Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31957</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31957</strong></p>
  <p>Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for in…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25791 – Sliver is a command and control framework that uses a custom Wireguard netstack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25791</guid>
    <pubDate>Mon, 09 Feb 2026 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25791</strong></p>
  <p>Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated remote actor can repeatedly create sessi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63387 – Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63387</guid>
    <pubDate>Thu, 18 Dec 2025 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63387</strong></p>
  <p>Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unaut…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63386 – A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63386</guid>
    <pubDate>Thu, 18 Dec 2025 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63386</strong></p>
  <p>A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9991 – The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9991</guid>
    <pubDate>Tue, 30 Sep 2025 11:37:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9991</strong></p>
  <p>The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive dat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59052 – Angular is a development platform for building mobile and desktop web applicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59052</guid>
    <pubDate>Wed, 10 Sep 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59052</strong></p>
  <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side rendering. For historical reasons, the container was stored as a JavaScript module-scoped global variable. When multiple requests are processed concurrently, they…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59042 – PyInstaller bundles a Python application and all its dependencies into a single ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59042</guid>
    <pubDate>Tue, 09 Sep 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59042</strong></p>
  <p>PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script attempting to load an optional module for bytecode decryption while this entry is still present in `sys.path`, an application built with PyInstaller < 6.0.0 may…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8904 – Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8904</guid>
    <pubDate>Wed, 13 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8904</strong></p>
  <p>Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges.     Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32672 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32672</guid>
    <pubDate>Fri, 11 Apr 2025 09:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32672</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Ultimate Bootstrap Elements for Elementor ultimate-bootstrap-elements-for-elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through <= 1.4.9.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26551 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26551</guid>
    <pubDate>Thu, 13 Feb 2025 14:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26551</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse bootstrap-collapse allows Stored XSS.This issue affects Bootstrap collapse: from n/a through <= 1.0.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13545 – The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13545</guid>
    <pubDate>Fri, 24 Jan 2025 09:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13545</strong></p>
  <p>The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases wher…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24030 – Envoy Gateway is an open source project for managing Envoy Proxy as a standalone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24030</guid>
    <pubDate>Thu, 23 Jan 2025 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24030</strong></p>
  <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy config…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-419</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49677 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49677</guid>
    <pubDate>Wed, 18 Dec 2024 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49677</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Bootstrap Buttons bootstrap-buttons allows Reflected XSS.This issue affects Bootstrap Buttons: from n/a through <= 1.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53824 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53824</guid>
    <pubDate>Fri, 06 Dec 2024 14:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53824</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows PHP Local File Inclusion.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.19.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11402 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11402</guid>
    <pubDate>Thu, 28 Nov 2024 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11402</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kubiq Block Editor Bootstrap Blocks block-editor-bootstrap-blocks allows Reflected XSS.This issue affects Block Editor Bootstrap Blocks: from n/a through <= 6.6.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52583 – The WesHacks GitHub repository provides the official Hackathon competition websi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52583</guid>
    <pubDate>Mon, 18 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52583</strong></p>
  <p>The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen Hackathon. The page `schedule.html` before 17 November 2024 or commit 93dfb83 contains links to `Leostop`, a site that hosts a malicious injected JavaScript file that occurs when bootstrap is run as well as jquery. `Leostop` may be a tracking malware and creates 2 JavaScript fi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50234 – In the Linux kernel, the following vulnerability has been resolved:

wifi: iwleg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50234</guid>
    <pubDate>Sat, 09 Nov 2024 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50234</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlegacy: Clear stale interrupts before resuming device  iwl4965 fails upon resume from hibernation on my laptop. The reason seems to be a stale interrupt which isn't being cleared out before interrupts are enabled. We end up with a race beween the resume trying to bring things back up, and the restart work (queued form th…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43140 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43140</guid>
    <pubDate>Tue, 13 Aug 2024 12:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43140</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40392 – SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40392</guid>
    <pubDate>Tue, 16 Jul 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40392</strong></p>
  <p>SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37462 – Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37462</guid>
    <pubDate>Tue, 09 Jul 2024 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37462</strong></p>
  <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows Path Traversal.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.2.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37293 – The AWS Deployment Framework (ADF) is a framework to manage and deploy resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37293</guid>
    <pubDate>Tue, 11 Jun 2024 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37293</strong></p>
  <p>The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking advantage of services such as AWS CodePipeline, AWS CodeBuild, and AWS CodeCommit to al…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31823 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31823</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31823</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31822 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31822</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31822</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31821 – SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31821</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31821</strong></p>
  <p>SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31820 – An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31820</guid>
    <pubDate>Mon, 29 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31820</strong></p>
  <p>An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27294 – dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27294</guid>
    <pubDate>Thu, 29 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27294</strong></p>
  <p>dp-golang is a Puppet module for Go installations.  Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52196 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52196</guid>
    <pubDate>Mon, 08 Jan 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52196</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39417 – IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39417</guid>
    <pubDate>Fri, 11 Aug 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39417</strong></p>
  <p>IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37895 – Java object deserialization issue in Jackrabbit webapp/standalone on all platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37895</guid>
    <pubDate>Tue, 25 Jul 2023 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37895</strong></p>
  <p>Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that can be used for remote code execution over RMI.  Users are advised to immediately update to versions 2.20.11 or 2.21.18.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-31442 – In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31442</guid>
    <pubDate>Thu, 11 May 2023 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-31442</strong></p>
  <p>In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing discovery does not validate (e.g., via TLS) the authenticity of the discovered service, this may result in exfiltration…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33294 – Transient DOS in Modem due to NULL pointer dereference while receiving response ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33294</guid>
    <pubDate>Thu, 13 Apr 2023 07:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33294</strong></p>
  <p>Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32563 – An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin creden...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32563</guid>
    <pubDate>Fri, 10 Jun 2022 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32563</strong></p>
  <p>An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials provided to the Admin REST API are ignored, resulting in privilege escalation for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26650 – In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.match...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26650</guid>
    <pubDate>Tue, 17 May 2022 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26650</strong></p>
  <p>In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1452 – Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1452</guid>
    <pubDate>Sun, 24 Apr 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1452</strong></p>
  <p>Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/12…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20198 – A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20198</guid>
    <pubDate>Tue, 23 Feb 2021 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20198</strong></p>
  <p>A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated `/exec` requests to execute arbitrary commands with…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15229 – Singularity (an open source container platform) from version 3.1.1 through 3.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15229</guid>
    <pubDate>Wed, 14 Oct 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15229</strong></p>
  <p>Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs filesystem. The extraction occurs automatically for unprivileged (either installation…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18641 – In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18641</guid>
    <pubDate>Mon, 10 Feb 2020 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18641</strong></p>
  <p>In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17095 – A command injection vulnerability has been discovered in the bootstrap stage of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17095</guid>
    <pubDate>Mon, 27 Jan 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17095</strong></p>
  <p>A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17096 – A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17096</guid>
    <pubDate>Mon, 27 Jan 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17096</strong></p>
  <p>A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-8121 – An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8121</guid>
    <pubDate>Tue, 05 Nov 2019 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-8121</strong></p>
  <p>An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-13314 – virt-bootstrap 1.1.0 allows local users to discover a root password by listing a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13314</guid>
    <pubDate>Fri, 05 Jul 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-13314</strong></p>
  <p>virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10842 – Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10842</guid>
    <pubDate>Thu, 04 Apr 2019 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10842</strong></p>
  <p>Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7649 – global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multipl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7649</guid>
    <pubDate>Sun, 17 Feb 2019 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7649</strong></p>
  <p>global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14742 – An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14742</guid>
    <pubDate>Mon, 30 Jul 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14742</strong></p>
  <p>An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c during a memcpy.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14740 – An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14740</guid>
    <pubDate>Mon, 30 Jul 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14740</strong></p>
  <p>An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c while making a query.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-12918 – In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12918</guid>
    <pubDate>Wed, 27 Jun 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-12918</strong></p>
  <p>In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9450 – The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9450</guid>
    <pubDate>Mon, 30 Oct 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9450</strong></p>
  <p>The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8559 – The knife bootstrap command in chef Infra client before version 15.4.45 leaks th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8559</guid>
    <pubDate>Thu, 21 Sep 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8559</strong></p>
  <p>The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5685 – The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5685</guid>
    <pubDate>Thu, 13 Aug 2015 14:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5685</strong></p>
  <p>The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8509 – The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8509</guid>
    <pubDate>Fri, 31 Oct 2014 14:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8509</strong></p>
  <p>The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1571 – Directory traversal vulnerability in the bootstrap service in Cisco Unified Cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1571</guid>
    <pubDate>Thu, 10 Jun 2010 00:30:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1571</strong></p>
  <p>Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6171 – includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6171</guid>
    <pubDate>Thu, 19 Feb 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6171</strong></p>
  <p>includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6171">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
