Количество 365 324
Количество 365 324
GHSA-xxvh-jcpq-95qv
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.
GHSA-xxvh-8h9p-mpwj
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
GHSA-xxvh-7q9r-8cf8
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xxvh-5hwj-42pp
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
GHSA-xxvg-9x33-93vm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.
GHSA-xxvf-7jx2-3m69
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
GHSA-xxvf-6jpw-pp5x
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
GHSA-xxvc-c328-56m6
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
GHSA-xxvc-6xwm-7prp
A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service.
GHSA-xxvc-26j5-3mg9
Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.
GHSA-xxv9-w5hm-328j
Jenkins AppSpider Plugin missing permission checks
GHSA-xxv9-fp7w-qg3h
Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.
GHSA-xxv9-73gc-96fm
LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.
GHSA-xxv9-6fj9-h72p
An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php.
GHSA-xxv8-wfjw-6w8f
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xxv8-pv43-57x5
PEAR core file overwrite vulnerability
GHSA-xxv8-mwpq-qmc2
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.
GHSA-xxv7-22hc-322m
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
GHSA-xxv6-qqx2-xg5m
A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-xxv6-pjw8-v27v
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxvh-jcpq-95qv File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | CVSS3: 9.8 | 24% Средний | больше 2 лет назад | |
GHSA-xxvh-8h9p-mpwj Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
GHSA-xxvh-7q9r-8cf8 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад | |||
GHSA-xxvh-5hwj-42pp OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation | 0% Низкий | 7 месяцев назад | ||
GHSA-xxvg-9x33-93vm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xxvf-7jx2-3m69 An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-xxvf-6jpw-pp5x A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 3.7 | 1% Низкий | почти 2 года назад | |
GHSA-xxvc-c328-56m6 A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text. | 0% Низкий | больше 1 года назад | ||
GHSA-xxvc-6xwm-7prp A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-xxvc-26j5-3mg9 Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing. | 0% Низкий | больше 4 лет назад | ||
GHSA-xxv9-w5hm-328j Jenkins AppSpider Plugin missing permission checks | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xxv9-fp7w-qg3h Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxv9-73gc-96fm LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution. | 1% Низкий | 7 месяцев назад | ||
GHSA-xxv9-6fj9-h72p An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xxv8-wfjw-6w8f Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 1% Низкий | почти 3 года назад | |
GHSA-xxv8-pv43-57x5 PEAR core file overwrite vulnerability | CVSS3: 7.5 | 13% Средний | больше 4 лет назад | |
GHSA-xxv8-mwpq-qmc2 Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file. | 7% Низкий | больше 4 лет назад | ||
GHSA-xxv7-22hc-322m A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-xxv6-qqx2-xg5m A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-xxv6-pjw8-v27v Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад |
Уязвимостей на страницу