Количество 315 253
Количество 315 253
GHSA-44w5-q257-8428
Exposure of password hashes in notrinos/notrinos-erp
GHSA-44w4-f424-89xh
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
GHSA-44w3-wrmw-j9hx
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
GHSA-44w3-qvp9-4hh4
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
GHSA-44w3-4x9p-xmff
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
GHSA-44w2-xrgw-gqvj
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.
GHSA-44w2-crmp-vc4v
Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.
GHSA-44w2-cgm4-695p
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.
GHSA-44w2-c6gq-2xxx
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
GHSA-44vx-q8jj-wcwm
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
GHSA-44vx-c3xh-577j
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.
GHSA-44vw-x4jf-3q2f
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
GHSA-44vw-5m8p-p6fc
Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.
GHSA-44vv-qwrx-c34r
Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
GHSA-44vv-mm86-7cg6
phpMyAdmin server-side request forgery (SSRF)
GHSA-44vv-j7c4-9vf4
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
GHSA-44vv-6vcv-9h7r
Windows Telephony Service Remote Code Execution Vulnerability
GHSA-44vv-4w2p-9wqf
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.
GHSA-44vv-2mpg-8hv5
Microsoft Office OneNote Remote Code Execution Vulnerability
GHSA-44vr-rwwj-p88h
Shescape vulnerable to insufficient escaping of whitespace
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-44w5-q257-8428 Exposure of password hashes in notrinos/notrinos-erp | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-44w4-f424-89xh IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | CVSS3: 4.8 | 0% Низкий | около 1 года назад | |
GHSA-44w3-wrmw-j9hx IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970. | CVSS3: 8.5 | 0% Низкий | больше 3 лет назад | |
GHSA-44w3-qvp9-4hh4 In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-44w3-4x9p-xmff The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. | CVSS3: 8.8 | 0% Низкий | около 1 года назад | |
GHSA-44w2-xrgw-gqvj Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695. | 0% Низкий | больше 3 лет назад | ||
GHSA-44w2-crmp-vc4v Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-44w2-cgm4-695p A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined. | 1% Низкий | 6 месяцев назад | ||
GHSA-44w2-c6gq-2xxx IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-44vx-q8jj-wcwm Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | 0% Низкий | больше 3 лет назад | ||
GHSA-44vx-c3xh-577j Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
GHSA-44vw-x4jf-3q2f MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-44vw-5m8p-p6fc Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action. | 1% Низкий | почти 4 года назад | ||
GHSA-44vv-qwrx-c34r Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-44vv-mm86-7cg6 phpMyAdmin server-side request forgery (SSRF) | CVSS3: 8.6 | 0% Низкий | больше 3 лет назад | |
GHSA-44vv-j7c4-9vf4 Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | CVSS3: 6.3 | 0% Низкий | около 2 лет назад | |
GHSA-44vv-6vcv-9h7r Windows Telephony Service Remote Code Execution Vulnerability | CVSS3: 8.8 | 6% Низкий | около 1 года назад | |
GHSA-44vv-4w2p-9wqf In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-44vv-2mpg-8hv5 Microsoft Office OneNote Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 2 года назад | |
GHSA-44vr-rwwj-p88h Shescape vulnerable to insufficient escaping of whitespace | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу