Количество 375 453
Количество 375 453
GHSA-xv5x-v758-wfgm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.
GHSA-xv5x-m38x-3h28
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.
GHSA-xv5x-6w3r-qqm9
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.
GHSA-xv5w-q9qp-mpg2
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xv5w-q5wq-r3c3
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
GHSA-xv5w-cw7x-72gj
id: pretty-print uses effective GID instead of effective UID for name lookup
GHSA-xv5v-c2mf-pc43
A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
GHSA-xv5v-4g23-pxj9
Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.
GHSA-xv5r-jf97-8xjm
An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.
GHSA-xv5r-44m2-6q3g
An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.
GHSA-xv5q-xvvq-gvcm
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.
GHSA-xv5q-r8xx-69mw
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.
GHSA-xv5p-prx7-chgr
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.
GHSA-xv5p-fjw5-vrj6
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
GHSA-xv5j-xw3x-cwr6
Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
GHSA-xv5j-gfm8-3c7j
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
GHSA-xv5h-v7jh-p2qh
Authentication bypass for specific endpoint
GHSA-xv5h-ppvh-6vp3
There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.
GHSA-xv5h-j798-x927
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
GHSA-xv5g-r83r-j2g9
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xv5x-v758-wfgm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-xv5x-m38x-3h28 Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xv5x-6w3r-qqm9 Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. | 2% Низкий | больше 4 лет назад | ||
GHSA-xv5w-q9qp-mpg2 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад | |||
GHSA-xv5w-q5wq-r3c3 Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client | CVSS3: 7.5 | 1% Низкий | 10 месяцев назад | |
GHSA-xv5w-cw7x-72gj id: pretty-print uses effective GID instead of effective UID for name lookup | CVSS3: 3.3 | 0% Низкий | 3 месяца назад | |
GHSA-xv5v-c2mf-pc43 A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-xv5v-4g23-pxj9 Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | 8% Низкий | больше 4 лет назад | ||
GHSA-xv5r-jf97-8xjm An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code. | 1% Низкий | почти 5 лет назад | ||
GHSA-xv5r-44m2-6q3g An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user. | CVSS3: 4.1 | 0% Низкий | больше 2 лет назад | |
GHSA-xv5q-xvvq-gvcm Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-xv5q-r8xx-69mw Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface. | CVSS3: 9.8 | 6% Низкий | больше 4 лет назад | |
GHSA-xv5p-prx7-chgr Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning. | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
GHSA-xv5p-fjw5-vrj6 Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer | CVSS3: 8.8 | 1% Низкий | 10 месяцев назад | |
GHSA-xv5j-xw3x-cwr6 Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-xv5j-gfm8-3c7j BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI. | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-xv5h-v7jh-p2qh Authentication bypass for specific endpoint | 67% Средний | больше 5 лет назад | ||
GHSA-xv5h-ppvh-6vp3 There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch. | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
GHSA-xv5h-j798-x927 Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium) | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xv5g-r83r-j2g9 Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу