Количество 314 691
Количество 314 691
GHSA-xvcq-gm57-37c5
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.
GHSA-xvcp-f5rw-f54w
A?CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')?vulnerability exists?that could cause?a path traversal issue?when?using the File Command.
GHSA-xvcp-85rr-xfr8
A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
GHSA-xvcp-33rc-j8gq
Insecure Unserialize in TYPO3 Import/Export
GHSA-xvcm-5qj2-5972
The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xvcj-qw55-xx42
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
GHSA-xvcj-9449-w85c
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_whitelisted_users_option', and 'wploti_uploaded_animation_save_option' functions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify certain plugin settings.
GHSA-xvch-r4wf-h8w9
Improper Certificate Validation in proton-j
GHSA-xvch-q88g-j649
The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-xvch-pp92-23j8
Windows Installer Elevation of Privilege Vulnerability
GHSA-xvch-fv6q-gx5m
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
GHSA-xvch-5gv4-984h
Prototype Pollution in minimist
GHSA-xvcg-x6pj-6267
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload.
GHSA-xvcg-hv6h-729g
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.
GHSA-xvcg-ff9f-p7x7
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.
GHSA-xvcg-crx7-qcjv
Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.
GHSA-xvcg-2q82-r87j
Panic mishandled in libpulse-binding
GHSA-xvcc-h99r-vm8p
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
GHSA-xvcc-fffc-h2p4
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
GHSA-xvc9-xwgj-4cq9
Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvcq-gm57-37c5 LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
GHSA-xvcp-f5rw-f54w A?CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')?vulnerability exists?that could cause?a path traversal issue?when?using the File Command. | CVSS3: 9.8 | 25% Средний | больше 2 лет назад | |
GHSA-xvcp-85rr-xfr8 A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | 20% Средний | больше 3 лет назад | ||
GHSA-xvcp-33rc-j8gq Insecure Unserialize in TYPO3 Import/Export | CVSS3: 6.3 | больше 1 года назад | ||
GHSA-xvcm-5qj2-5972 The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
GHSA-xvcj-qw55-xx42 EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability. | CVSS3: 6 | 0% Низкий | больше 1 года назад | |
GHSA-xvcj-9449-w85c The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_whitelisted_users_option', and 'wploti_uploaded_animation_save_option' functions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify certain plugin settings. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-xvch-r4wf-h8w9 Improper Certificate Validation in proton-j | CVSS3: 7.4 | 0% Низкий | около 7 лет назад | |
GHSA-xvch-q88g-j649 The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvch-pp92-23j8 Windows Installer Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xvch-fv6q-gx5m Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 5.9 | 2% Низкий | больше 3 лет назад | |
GHSA-xvch-5gv4-984h Prototype Pollution in minimist | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-xvcg-x6pj-6267 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xvcg-hv6h-729g PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xvcg-ff9f-p7x7 SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvcg-crx7-qcjv Weaver Ecology v9* was discovered to contain a SQL injection vulnerability. | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
GHSA-xvcg-2q82-r87j Panic mishandled in libpulse-binding | CVSS3: 7.5 | 0% Низкий | около 4 лет назад | |
GHSA-xvcc-h99r-vm8p An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvcc-fffc-h2p4 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version. | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад | |
GHSA-xvc9-xwgj-4cq9 Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service | CVSS3: 7.5 | больше 3 лет назад |
Уязвимостей на страницу