Количество 314 928
Количество 314 928
GHSA-44cm-p9q7-rr3p
Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs
GHSA-44cj-54hp-jr6f
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.
GHSA-44ch-2f85-f4rm
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.
GHSA-44cg-qcpr-fwjh
Cross site scripting in francoisjacquet/rosariosis
GHSA-44cg-m8vj-gr6h
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information.
GHSA-44cg-7j74-fvp3
Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.
GHSA-44cf-cppv-qcvq
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-44cc-c4hq-r7vv
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.
GHSA-44cc-43rp-5947
JupyterLab vulnerable to potential authentication and CSRF tokens leak
GHSA-44c9-7g74-x3pf
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
GHSA-44c7-rp6q-gcrh
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
GHSA-44c7-hc99-224f
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.
GHSA-44c7-h9h2-wj6v
Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission.
GHSA-44c7-chxm-hq3q
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
GHSA-44c7-92p2-r6w4
The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot
GHSA-44c7-8q42-vpfv
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
GHSA-44c7-43g3-f86m
An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.
GHSA-44c7-327r-j4x7
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
GHSA-44c7-2233-xwr4
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
GHSA-44c6-4v22-4mhx
semver-regex Regular Expression Denial of Service (ReDOS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-44cm-p9q7-rr3p Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-44cj-54hp-jr6f Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF. | 13% Средний | почти 4 года назад | ||
GHSA-44ch-2f85-f4rm Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it. | 4% Низкий | почти 4 года назад | ||
GHSA-44cg-qcpr-fwjh Cross site scripting in francoisjacquet/rosariosis | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-44cg-m8vj-gr6h Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information. | 81% Высокий | больше 3 лет назад | ||
GHSA-44cg-7j74-fvp3 Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests. | 0% Низкий | больше 3 лет назад | ||
GHSA-44cf-cppv-qcvq A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-44cc-c4hq-r7vv The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015. | 5% Низкий | больше 3 лет назад | ||
GHSA-44cc-43rp-5947 JupyterLab vulnerable to potential authentication and CSRF tokens leak | CVSS3: 7.6 | 0% Низкий | около 2 лет назад | |
GHSA-44c9-7g74-x3pf IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-44c7-rp6q-gcrh In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service. | 1% Низкий | больше 3 лет назад | ||
GHSA-44c7-hc99-224f libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-44c7-h9h2-wj6v Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-44c7-chxm-hq3q Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. | CVSS3: 9.8 | 14% Средний | около 1 года назад | |
GHSA-44c7-92p2-r6w4 The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-44c7-8q42-vpfv core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter. | CVSS3: 9.8 | 51% Средний | больше 3 лет назад | |
GHSA-44c7-43g3-f86m An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length. | CVSS3: 7.2 | 0% Низкий | 8 месяцев назад | |
GHSA-44c7-327r-j4x7 Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability." | CVSS3: 6.5 | 15% Средний | больше 3 лет назад | |
GHSA-44c7-2233-xwr4 Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability." | 41% Средний | больше 3 лет назад | ||
GHSA-44c6-4v22-4mhx semver-regex Regular Expression Denial of Service (ReDOS) | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу