Количество 354 225
Количество 354 225
GHSA-xw5j-5p2q-fr86
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
GHSA-xw5j-4h78-77h2
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
GHSA-xw5h-h3cf-m4mx
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
GHSA-xw5h-cmh3-8j6j
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
GHSA-xw5h-8j92-59pp
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
GHSA-xw5g-qgw7-x534
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805
GHSA-xw5g-39g7-vh7x
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
GHSA-xw5f-m9q2-678f
Microsoft SharePoint Denial of Service Update
GHSA-xw5f-g937-wgm2
ChakraCore RCE Vulnerability
GHSA-xw5f-2w3q-6c92
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.
GHSA-xw5c-xwc7-95gf
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
GHSA-xw5c-jc7x-gf75
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
GHSA-xw59-hvm2-8pj6
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
GHSA-xw59-4mp5-9chf
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.
GHSA-xw58-crph-crhm
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
GHSA-xw58-64fr-3323
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files.
GHSA-xw57-xggj-g8vq
SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.
GHSA-xw57-qhqx-v67p
A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.
GHSA-xw57-23p8-9wc5
@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-xw55-hvqx-m963
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xw5j-5p2q-fr86 Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-xw5j-4h78-77h2 Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
GHSA-xw5h-h3cf-m4mx Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-xw5h-cmh3-8j6j Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-xw5h-8j92-59pp open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xw5g-qgw7-x534 In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805 | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-xw5g-39g7-vh7x Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product. | CVSS3: 7.2 | 1% Низкий | около 4 лет назад | |
GHSA-xw5f-m9q2-678f Microsoft SharePoint Denial of Service Update | CVSS3: 5 | 2% Низкий | около 4 лет назад | |
GHSA-xw5f-g937-wgm2 ChakraCore RCE Vulnerability | CVSS3: 7.5 | 9% Низкий | около 4 лет назад | |
GHSA-xw5f-2w3q-6c92 An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241. | CVSS3: 8.3 | 3% Низкий | около 4 лет назад | |
GHSA-xw5c-xwc7-95gf Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0. | CVSS3: 5.3 | 4% Низкий | больше 3 лет назад | |
GHSA-xw5c-jc7x-gf75 PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-xw59-hvm2-8pj6 DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost | CVSS3: 8.1 | 0% Низкий | 4 месяца назад | |
GHSA-xw59-4mp5-9chf A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564. | CVSS3: 7 | 3% Низкий | около 4 лет назад | |
GHSA-xw58-crph-crhm Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution. | CVSS3: 9.8 | 40% Средний | больше 2 лет назад | |
GHSA-xw58-64fr-3323 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xw57-xggj-g8vq SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-xw57-qhqx-v67p A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file. | CVSS3: 6.8 | 0% Низкий | больше 1 года назад | |
GHSA-xw57-23p8-9wc5 @asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range) | около 1 месяца назад | |||
GHSA-xw55-hvqx-m963 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 7 месяцев назад |
Уязвимостей на страницу