Количество 373 528
Количество 373 528
GHSA-xxp4-q5hx-j33x
WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.
GHSA-xxp4-mf4h-6cwm
Moodle vulnerable to Server Side Request Forgery
GHSA-xxp4-hw2v-2vcr
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
GHSA-xxp3-mm76-hhf2
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
GHSA-xxp3-fcv5-mx3m
JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.
GHSA-xxp2-xgc8-48h8
Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.
GHSA-xxp2-cp36-7xm7
Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.
GHSA-xxp2-9c9g-7wmj
XWiki Platform: Remote code execution from edit in multilingual wikis via translations
GHSA-xxmw-m6v2-9h47
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).
GHSA-xxmv-v72m-r6w4
The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.
GHSA-xxmv-mjx9-wg53
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.
GHSA-xxmr-5pw7-p42v
Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.
GHSA-xxmr-593v-8f45
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
GHSA-xxmr-226v-fr48
Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Submissions: from n/a through 0.26.
GHSA-xxmq-q3f3-wvpg
A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.
GHSA-xxmq-pq4f-q6mv
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.
GHSA-xxmq-p542-3257
Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.
GHSA-xxmq-8hjh-8rjg
A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
GHSA-xxmq-4vph-956w
Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)
GHSA-xxmp-4c36-6f47
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxp4-q5hx-j33x WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4. | 2% Низкий | больше 4 лет назад | ||
GHSA-xxp4-mf4h-6cwm Moodle vulnerable to Server Side Request Forgery | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-xxp4-hw2v-2vcr In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xxp3-mm76-hhf2 EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | 2% Низкий | больше 4 лет назад | ||
GHSA-xxp3-fcv5-mx3m JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxp2-xgc8-48h8 Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-xxp2-cp36-7xm7 Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field. | 2% Низкий | больше 4 лет назад | ||
GHSA-xxp2-9c9g-7wmj XWiki Platform: Remote code execution from edit in multilingual wikis via translations | CVSS3: 9.9 | 1% Низкий | больше 2 лет назад | |
GHSA-xxmw-m6v2-9h47 A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)). | CVSS3: 5.5 | 1% Низкий | больше 2 лет назад | |
GHSA-xxmv-v72m-r6w4 The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. | 4% Низкий | больше 4 лет назад | ||
GHSA-xxmv-mjx9-wg53 Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxmr-5pw7-p42v Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxmr-593v-8f45 In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-xxmr-226v-fr48 Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Submissions: from n/a through 0.26. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-xxmq-q3f3-wvpg A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxmq-pq4f-q6mv This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-xxmq-p542-3257 Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xxmq-8hjh-8rjg A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | CVSS3: 7.3 | 1% Низкий | 8 месяцев назад | |
GHSA-xxmq-4vph-956w Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048) | CVSS3: 5.3 | больше 3 лет назад | ||
GHSA-xxmp-4c36-6f47 Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу