Количество 314 691
Количество 314 691
GHSA-xv87-5fp5-4jrj
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.
GHSA-xv87-56gx-3f4x
Windows Extended Negotiation Denial of Service Vulnerability
GHSA-xv86-gr62-vcj7
This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity.
GHSA-xv86-79r9-q5jh
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
GHSA-xv86-3hxg-hv4r
Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.
GHSA-xv84-c645-853v
The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.
GHSA-xv84-3fv6-rp2r
ims_ex is a vendor system service used to manage VoLTE in unisoc devices?But it does not verify the caller's permissions?so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634
GHSA-xv83-x443-7rmw
HTML injection in search results via plaintext message highlighting
GHSA-xv83-vfqj-3xg9
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-xv82-mgrr-4j2f
Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.
GHSA-xv82-93gj-h8jq
Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing while using global variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
GHSA-xv7x-x6wr-xx7g
Apache Ranger policy engine incorrectly matches paths in certain conditions
GHSA-xv7x-vj5h-3pqq
A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as critical. This issue affects some unknown processing of the file request.php. The manipulation of the argument phone leads to sql injection. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 264813c546dba03989ac0fc365f2022bf65e3be2. It is recommended to apply a patch to fix this issue.
GHSA-xv7x-v825-68c4
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
GHSA-xv7x-qjw2-9399
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.
GHSA-xv7x-q4ch-37fx
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.
GHSA-xv7v-rr53-498m
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.
GHSA-xv7v-rf6g-xwrc
Directory Traversal in typo3/phar-stream-wrapper
GHSA-xv7r-9vq4-9wrq
Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting
GHSA-xv7r-5ggj-8grr
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xv87-5fp5-4jrj Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. | 2% Низкий | почти 4 года назад | ||
GHSA-xv87-56gx-3f4x Windows Extended Negotiation Denial of Service Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-xv86-gr62-vcj7 This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity. | 2% Низкий | 10 месяцев назад | ||
GHSA-xv86-79r9-q5jh An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-xv86-3hxg-hv4r Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes. | 0% Низкий | больше 3 лет назад | ||
GHSA-xv84-c645-853v The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xv84-3fv6-rp2r ims_ex is a vendor system service used to manage VoLTE in unisoc devices?But it does not verify the caller's permissions?so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634 | CVSS3: 9.1 | 0% Низкий | почти 4 года назад | |
GHSA-xv83-x443-7rmw HTML injection in search results via plaintext message highlighting | CVSS3: 8.2 | 0% Низкий | почти 3 года назад | |
GHSA-xv83-vfqj-3xg9 Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xv82-mgrr-4j2f Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5. | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-xv82-93gj-h8jq Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing while using global variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24 | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xv7x-x6wr-xx7g Apache Ranger policy engine incorrectly matches paths in certain conditions | CVSS3: 5.9 | 1% Низкий | больше 7 лет назад | |
GHSA-xv7x-vj5h-3pqq A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as critical. This issue affects some unknown processing of the file request.php. The manipulation of the argument phone leads to sql injection. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 264813c546dba03989ac0fc365f2022bf65e3be2. It is recommended to apply a patch to fix this issue. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xv7x-v825-68c4 TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter. | CVSS3: 9.8 | 4% Низкий | 10 месяцев назад | |
GHSA-xv7x-qjw2-9399 SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action. | 0% Низкий | почти 4 года назад | ||
GHSA-xv7x-q4ch-37fx The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s. | 13% Средний | больше 3 лет назад | ||
GHSA-xv7v-rr53-498m A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion. | 0% Низкий | больше 3 лет назад | ||
GHSA-xv7v-rf6g-xwrc Directory Traversal in typo3/phar-stream-wrapper | CVSS3: 9.8 | 11% Средний | больше 4 лет назад | |
GHSA-xv7r-9vq4-9wrq Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xv7r-5ggj-8grr An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data. | CVSS3: 3.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу