Количество 324 648
Количество 324 648
GHSA-xrjf-q592-pcrw
A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused.
GHSA-xrjf-phvv-r4vr
Command injection in strapi
GHSA-xrjf-j24x-4gqj
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503.
GHSA-xrj9-vwwj-2w2c
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.
GHSA-xrj9-mw57-j34v
AstrBot contains a directory traversal vulnerability
GHSA-xrj9-h79q-8446
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.
GHSA-xrj9-8xhq-9gjh
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.
GHSA-xrj9-7qw9-gvw5
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
GHSA-xrj9-73xw-fr4f
Payment Orchestrator Service Elevation of Privilege Vulnerability
GHSA-xrj7-x7gp-wwqr
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
GHSA-xrj7-v4x4-74hr
A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.
GHSA-xrj7-5h89-vjmj
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.
GHSA-xrj7-4gfh-q9h7
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
GHSA-xrj6-x752-mhrf
A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xrj6-cww5-qm75
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
GHSA-xrj6-96j3-q3jj
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
GHSA-xrj6-9329-h97g
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.
GHSA-xrj4-x4gq-r76x
Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.
GHSA-xrj4-gqr5-5gq8
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.
GHSA-xrj4-fxgw-43xg
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xrjf-q592-pcrw A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused. | CVSS3: 4.9 | 0% Низкий | почти 4 года назад | |
GHSA-xrjf-phvv-r4vr Command injection in strapi | CVSS3: 6.1 | 0% Низкий | около 4 лет назад | |
GHSA-xrjf-j24x-4gqj A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-xrj9-vwwj-2w2c PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. | 66% Средний | почти 4 года назад | ||
GHSA-xrj9-mw57-j34v AstrBot contains a directory traversal vulnerability | 1% Низкий | 5 месяцев назад | ||
GHSA-xrj9-h79q-8446 Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service. | 1% Низкий | почти 4 года назад | ||
GHSA-xrj9-8xhq-9gjh A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges. | CVSS3: 9.8 | 33% Средний | почти 4 года назад | |
GHSA-xrj9-7qw9-gvw5 Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | 0% Низкий | почти 4 года назад | ||
GHSA-xrj9-73xw-fr4f Payment Orchestrator Service Elevation of Privilege Vulnerability | CVSS3: 8.6 | 0% Низкий | около 1 месяца назад | |
GHSA-xrj7-x7gp-wwqr Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-xrj7-v4x4-74hr A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability. | CVSS3: 3.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-xrj7-5h89-vjmj An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known. | 0% Низкий | почти 4 года назад | ||
GHSA-xrj7-4gfh-q9h7 Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. | CVSS3: 6.1 | 5% Низкий | больше 4 лет назад | |
GHSA-xrj6-x752-mhrf A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 7.3 | 0% Низкий | 20 дней назад | |
GHSA-xrj6-cww5-qm75 phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-xrj6-96j3-q3jj A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xrj6-9329-h97g Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property. | 1% Низкий | почти 4 года назад | ||
GHSA-xrj4-x4gq-r76x Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request. | 6% Низкий | почти 4 года назад | ||
GHSA-xrj4-gqr5-5gq8 Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1. | CVSS3: 8.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xrj4-fxgw-43xg An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI. | CVSS3: 5.7 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу