Количество 375 356
Количество 375 356
GHSA-xvrg-j7m3-pwcr
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.
GHSA-xvrg-83h8-x5v4
Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.
GHSA-xvrf-q22w-5f48
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.
GHSA-xvrf-gvhf-wxf6
Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.
GHSA-xvrf-3569-2x76
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
GHSA-xvrc-cwrh-jw5g
Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0.
GHSA-xvrc-2wvh-49vc
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.
GHSA-xvr9-jr9p-grf3
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.
GHSA-xvr9-h38m-rc5q
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks
GHSA-xvr9-fr69-g722
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter.
GHSA-xvr9-7fjx-5335
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.
GHSA-xvr9-35cr-46v9
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
GHSA-xvr9-244h-6gg8
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
GHSA-xvr8-rwv3-hv45
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.
GHSA-xvr8-rhg7-pv7w
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.
GHSA-xvr7-xmmp-p9vr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.
GHSA-xvr7-p2c6-j83w
swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability
GHSA-xvr7-j937-8w46
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag.
GHSA-xvr7-55fh-xx8f
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
GHSA-xvr6-m6gq-m42f
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvrg-j7m3-pwcr Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvrg-83h8-x5v4 Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvrf-q22w-5f48 ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xvrf-gvhf-wxf6 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvrf-3569-2x76 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xvrc-cwrh-jw5g Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0. | CVSS3: 8.8 | 0% Низкий | около 1 года назад | |
GHSA-xvrc-2wvh-49vc Gitsign's Rekor public keys fetched from upstream API instead of local TUF client. | CVSS3: 4.2 | 0% Низкий | почти 3 года назад | |
GHSA-xvr9-jr9p-grf3 PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code. | CVSS3: 8.8 | 3% Низкий | больше 4 лет назад | |
GHSA-xvr9-h38m-rc5q The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks | 1% Низкий | почти 5 лет назад | ||
GHSA-xvr9-fr69-g722 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to modify arbitrary posts (e.g. unpublish published posts and overwrite the contents) via the 'post_id' parameter. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-xvr9-7fjx-5335 Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvr9-35cr-46v9 org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context | CVSS3: 5.9 | 0% Низкий | 23 дня назад | |
GHSA-xvr9-244h-6gg8 Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-xvr8-rwv3-hv45 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox. | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
GHSA-xvr8-rhg7-pv7w Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvr7-xmmp-p9vr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xvr7-p2c6-j83w swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability | около 1 года назад | |||
GHSA-xvr7-j937-8w46 Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvr7-55fh-xx8f Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvr6-m6gq-m42f SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу