Количество 353 489
Количество 353 489
GHSA-xxq2-fm9w-xjv8
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks
GHSA-xxq2-74hw-vg6m
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability
GHSA-xxq2-62cv-vmcw
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
GHSA-xxpx-w698-q23j
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below
GHSA-xxpx-f58m-683f
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
GHSA-xxpw-32hf-q8v9
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
GHSA-xxpv-mm3c-74x5
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
GHSA-xxpv-gwrv-58xv
Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).
GHSA-xxpv-3q6j-c873
The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xxpr-8m4r-4fgq
Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265.
GHSA-xxpq-jv5h-r9hg
Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.
GHSA-xxpq-f82j-29cp
A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3. It has been classified as problematic. Affected is the function taxonomy_switcher_init of the file taxonomy-switcher.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.4 is able to address this issue. It is recommended to upgrade the affected component. VDB-217446 is the identifier assigned to this vulnerability.
GHSA-xxpq-8gj6-wc56
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.
GHSA-xxpq-7wg8-3p65
An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data.
GHSA-xxpp-m3m6-m3rm
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
GHSA-xxpp-89v4-96px
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
GHSA-xxpp-86hx-cjfg
IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341.
GHSA-xxpp-5mwm-33p3
IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675.
GHSA-xxpm-69vv-79hr
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later
GHSA-xxpj-q764-9r6q
NocoDB: Missing Ownership Check in MCP Attachment Read
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxq2-fm9w-xjv8 The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks | CVSS3: 4.9 | 0% Низкий | 7 месяцев назад | |
GHSA-xxq2-74hw-vg6m Jenkins WSO2 Oauth Plugin Session Fixation vulnerability | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-xxq2-62cv-vmcw Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-xxpx-w698-q23j When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-xxpx-f58m-683f Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-xxpw-32hf-q8v9 AVideo: Unauthenticated PHP session store exposed to host network via published memcached port | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
GHSA-xxpv-mm3c-74x5 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi. | 1% Низкий | около 4 лет назад | ||
GHSA-xxpv-gwrv-58xv Aten PE8108 2.4.232 is vulnerable to denial of service (DOS). | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-xxpv-3q6j-c873 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 7.2 | 1% Низкий | больше 2 лет назад | |
GHSA-xxpr-8m4r-4fgq Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265. | CVSS3: 7.8 | 14% Средний | около 4 лет назад | |
GHSA-xxpq-jv5h-r9hg Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xxpq-f82j-29cp A vulnerability was found in WebDevStudios taxonomy-switcher Plugin up to 1.0.3. It has been classified as problematic. Affected is the function taxonomy_switcher_init of the file taxonomy-switcher.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.4 is able to address this issue. It is recommended to upgrade the affected component. VDB-217446 is the identifier assigned to this vulnerability. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xxpq-8gj6-wc56 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access. | 1% Низкий | около 4 лет назад | ||
GHSA-xxpq-7wg8-3p65 An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
GHSA-xxpp-m3m6-m3rm Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
GHSA-xxpp-89v4-96px Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove. | CVSS3: 7.3 | 2% Низкий | около 4 лет назад | |
GHSA-xxpp-86hx-cjfg IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-xxpp-5mwm-33p3 IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130675. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xxpm-69vv-79hr An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later | CVSS3: 5.5 | 1% Низкий | больше 2 лет назад | |
GHSA-xxpj-q764-9r6q NocoDB: Missing Ownership Check in MCP Attachment Read | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу