Количество 312 573
Количество 312 573
GHSA-xw6w-ff6h-v543
Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-xw6v-xv6h-m7g3
A vulnerability has been found in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/PPTPServer. Such manipulation of the argument ip1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-xw6r-x75r-2fh4
The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."
GHSA-xw6r-r36q-4xx4
Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.
GHSA-xw6r-chmh-vpmj
Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
GHSA-xw6q-jj4q-5cjw
In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.
GHSA-xw6m-975g-mg7m
A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier VDB-272449 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xw6m-3m5q-mxpm
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
GHSA-xw6j-vwv7-j25v
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.
GHSA-xw6j-mq6v-pmv6
Jenkins SAML Single Sign On(SSO) Plugin Cross-Site Request Forgery vulnerability
GHSA-xw6g-jjvf-wwf9
Invalid file request can crash server
GHSA-xw6g-7x68-mrj2
A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xw69-vqf5-9v95
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
GHSA-xw67-vhv2-m2p4
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
GHSA-xw67-hqxc-2h5x
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.
GHSA-xw66-fwrq-35x6
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.
GHSA-xw66-7hgg-w34f
Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.
GHSA-xw65-r59v-qpqc
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
GHSA-xw65-jr46-vvcm
The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-xw65-g8p2-hc6q
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xw6w-ff6h-v543 Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | 6 месяцев назад | |
GHSA-xw6v-xv6h-m7g3 A vulnerability has been found in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/PPTPServer. Such manipulation of the argument ip1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.2 | 0% Низкий | около 1 месяца назад | |
GHSA-xw6r-x75r-2fh4 The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | 0% Низкий | почти 4 года назад | ||
GHSA-xw6r-r36q-4xx4 Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache. | 0% Низкий | почти 4 года назад | ||
GHSA-xw6r-chmh-vpmj Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails | 0% Низкий | 4 месяца назад | ||
GHSA-xw6q-jj4q-5cjw In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xw6m-975g-mg7m A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier VDB-272449 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
GHSA-xw6m-3m5q-mxpm Liferay Portal's Membership page is vulnerable to XSS through “name“ text field | 0% Низкий | 4 месяца назад | ||
GHSA-xw6j-vwv7-j25v Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages. | 0% Низкий | почти 4 года назад | ||
GHSA-xw6j-mq6v-pmv6 Jenkins SAML Single Sign On(SSO) Plugin Cross-Site Request Forgery vulnerability | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-xw6g-jjvf-wwf9 Invalid file request can crash server | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xw6g-7x68-mrj2 A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
GHSA-xw69-vqf5-9v95 laravel-bjyblog 6.1.1 has XSS via a crafted URL. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xw67-vhv2-m2p4 CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel. | 0% Низкий | больше 3 лет назад | ||
GHSA-xw67-hqxc-2h5x Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xw66-fwrq-35x6 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-xw66-7hgg-w34f Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp. | 1% Низкий | почти 4 года назад | ||
GHSA-xw65-r59v-qpqc An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xw65-jr46-vvcm The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-xw65-g8p2-hc6q It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу