Количество 314 928
Количество 314 928
GHSA-xv69-6rf3-w5g2
Missing permission check in Jenkins Cloud Statistics Plugin
GHSA-xv68-vxp8-qj76
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
GHSA-xv68-rrmw-9xwf
Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)
GHSA-xv67-vhc4-3v47
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2.
GHSA-xv66-85xp-gvq8
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings.
GHSA-xv65-m527-x787
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.
GHSA-xv64-wpfr-x2m3
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
GHSA-xv64-q73j-cvqp
Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.
GHSA-xv64-jjpm-mgjv
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
GHSA-xv64-cc6j-5cjp
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.
GHSA-xv64-8p4r-94gq
pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
GHSA-xv63-cpgc-6g6c
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334.
GHSA-xv63-838w-fgf7
ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.
GHSA-xv63-73qr-p568
In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.
GHSA-xv5x-v758-wfgm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.
GHSA-xv5x-m38x-3h28
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.
GHSA-xv5x-6w3r-qqm9
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.
GHSA-xv5w-q9qp-mpg2
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xv5w-q5wq-r3c3
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
GHSA-xv5v-c2mf-pc43
A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xv69-6rf3-w5g2 Missing permission check in Jenkins Cloud Statistics Plugin | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-xv68-vxp8-qj76 Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4. | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-xv68-rrmw-9xwf Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field) | CVSS3: 4.8 | 0% Низкий | больше 1 года назад | |
GHSA-xv67-vhc4-3v47 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-xv66-85xp-gvq8 The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings. | CVSS3: 2.7 | 0% Низкий | 5 месяцев назад | |
GHSA-xv65-m527-x787 Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. | CVSS3: 8.5 | 1% Низкий | почти 2 года назад | |
GHSA-xv64-wpfr-x2m3 The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xv64-q73j-cvqp Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-xv64-jjpm-mgjv DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system. | 0% Низкий | больше 3 лет назад | ||
GHSA-xv64-cc6j-5cjp DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters. | 0% Низкий | больше 3 лет назад | ||
GHSA-xv64-8p4r-94gq pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload | CVSS3: 7.4 | 0% Низкий | почти 2 года назад | |
GHSA-xv63-cpgc-6g6c An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334. | 12% Средний | больше 3 лет назад | ||
GHSA-xv63-838w-fgf7 ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xv63-73qr-p568 In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution. | 1% Низкий | больше 3 лет назад | ||
GHSA-xv5x-v758-wfgm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18. | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
GHSA-xv5x-m38x-3h28 Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-xv5x-6w3r-qqm9 Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. | 3% Низкий | почти 4 года назад | ||
GHSA-xv5w-q9qp-mpg2 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | около 1 месяца назад | |||
GHSA-xv5w-q5wq-r3c3 Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-xv5v-c2mf-pc43 A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу