Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
json project vulnerabilities and exploits
(subscribe to this query)
9.4
CVSSv3
CVE-2024-0964
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
Gradio Project Gradio -
1 Github repository
5.4
CVSSv3
CVE-2023-52265
IDURAR (aka idurar-erp-crm) up to and including 2.0.1 allows stored XSS via a PATCH request with a crafted JSON email template in the /api/email/update data.
Idurar Project Idurar
5.5
CVSSv3
CVE-2023-50246
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
Jqlang Jq 1.7
5.5
CVSSv3
CVE-2023-50268
jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.
Jqlang Jq 1.7
7.5
CVSSv3
CVE-2023-5072
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Json-java Project Json-java
2 Github repositories
9.8
CVSSv3
CVE-2021-32292
An issue exists in json-c from 20200420 (post 0.14 unreleased code) up to and including 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
Json-c Project Json-c 0.15-20200726
7.5
CVSSv3
CVE-2023-38337
rswag prior to 2.10.1 allows remote malicious users to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.
Rswag Project Rswag
8.2
CVSSv3
CVE-2023-35934
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for download fragments differs from their parent ...
Yt-dlp Project Yt-dlp
Youtube-dlc Project Youtube-dlc
Yt-dl Youtube-dl
Fedoraproject Fedora 37
Fedoraproject Fedora 38
7.5
CVSSv3
CVE-2023-34610
An issue exists json-io thru 4.14.0 allows malicious users to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Json-io Project Json-io
7.5
CVSSv3
CVE-2023-34612
An issue exists ph-json thru 9.5.5 allows malicious users to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Ph-json Project Ph-json
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-34377
CVE-2024-20859
CVE-2023-49606
inject
arbitrary
CVE-2024-33788
CVE-2024-30973
IDOR
CVE-2024-33907
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »