Количество 375 356
Количество 375 356
GHSA-xw5m-5vch-x6g5
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xw5j-gv2g-mjm2
Miscompilation in cortex-m-rt 0.7.1 and 0.7.2
GHSA-xw5j-8gp6-p2vj
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.
GHSA-xw5j-6ccc-rwh9
IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.
GHSA-xw5j-5p2q-fr86
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
GHSA-xw5j-4h78-77h2
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
GHSA-xw5h-h3cf-m4mx
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
GHSA-xw5h-cmh3-8j6j
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
GHSA-xw5h-8j92-59pp
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
GHSA-xw5h-2294-wjv4
In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-xw5g-qgw7-x534
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805
GHSA-xw5g-644p-8357
Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
GHSA-xw5g-39g7-vh7x
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
GHSA-xw5f-m9q2-678f
Microsoft SharePoint Denial of Service Update
GHSA-xw5f-g937-wgm2
ChakraCore RCE Vulnerability
GHSA-xw5f-2w3q-6c92
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.
GHSA-xw5c-xwc7-95gf
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.
GHSA-xw5c-jc7x-gf75
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
GHSA-xw59-hvm2-8pj6
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
GHSA-xw59-4mp5-9chf
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xw5m-5vch-x6g5 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-xw5j-gv2g-mjm2 Miscompilation in cortex-m-rt 0.7.1 and 0.7.2 | больше 3 лет назад | |||
GHSA-xw5j-8gp6-p2vj Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-xw5j-6ccc-rwh9 IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes. | 2% Низкий | больше 4 лет назад | ||
GHSA-xw5j-5p2q-fr86 Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-xw5j-4h78-77h2 Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
GHSA-xw5h-h3cf-m4mx Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-xw5h-cmh3-8j6j Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
GHSA-xw5h-8j92-59pp open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xw5h-2294-wjv4 In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.8 | 0% Низкий | 5 дней назад | |
GHSA-xw5g-qgw7-x534 In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805 | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xw5g-644p-8357 Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-xw5g-39g7-vh7x Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product. | CVSS3: 7.2 | 1% Низкий | около 4 лет назад | |
GHSA-xw5f-m9q2-678f Microsoft SharePoint Denial of Service Update | CVSS3: 5 | 2% Низкий | больше 4 лет назад | |
GHSA-xw5f-g937-wgm2 ChakraCore RCE Vulnerability | CVSS3: 7.5 | 9% Низкий | больше 4 лет назад | |
GHSA-xw5f-2w3q-6c92 An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241. | CVSS3: 8.3 | 3% Низкий | больше 4 лет назад | |
GHSA-xw5c-xwc7-95gf Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0. | CVSS3: 5.3 | 4% Низкий | больше 3 лет назад | |
GHSA-xw5c-jc7x-gf75 PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-xw59-hvm2-8pj6 DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost | CVSS3: 8.1 | 0% Низкий | 6 месяцев назад | |
GHSA-xw59-4mp5-9chf A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564. | CVSS3: 7 | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу