Количество 314 458
Количество 314 458
GHSA-42q7-95j7-w62m
Mautic is vulnerable to XSS vulnerability
GHSA-42q6-q2fj-4rjg
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
GHSA-42q6-p5h5-993x
Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.
GHSA-42q5-gvj7-g3c2
There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
GHSA-42q5-3w9f-c6pw
Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.
GHSA-42q4-wr7h-j9qx
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.
GHSA-42q4-9xf9-f67x
Apache Superset allowed for database connections password leak for authenticated users
GHSA-42q3-f5fp-gpxr
** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.
GHSA-42q2-w7pp-mx38
sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.
GHSA-42q2-m54f-jh95
sememos/memos vulnerable to Improper Handling of Values
GHSA-42px-vp8x-r9wx
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal.
GHSA-42pv-rvjf-mxph
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.
GHSA-42pr-hpj6-p97q
The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.
GHSA-42pq-hf34-5c7v
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
GHSA-42pq-h6rj-6c6q
Memory corruption in Core due to stack-based buffer overflow.
GHSA-42pq-634r-jghr
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
GHSA-42pp-ccmj-xrg8
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.
GHSA-42pm-gg43-38gr
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.
GHSA-42pj-96jc-q58w
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.
GHSA-42pj-35w6-4jwg
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-42q7-95j7-w62m Mautic is vulnerable to XSS vulnerability | CVSS3: 9.6 | 1% Низкий | больше 1 года назад | |
GHSA-42q6-q2fj-4rjg Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-42q6-p5h5-993x Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors. | 23% Средний | почти 4 года назад | ||
GHSA-42q5-gvj7-g3c2 There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. | 0% Низкий | больше 3 лет назад | ||
GHSA-42q5-3w9f-c6pw Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface. | CVSS3: 6.1 | 0% Низкий | 7 месяцев назад | |
GHSA-42q4-wr7h-j9qx The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-42q4-9xf9-f67x Apache Superset allowed for database connections password leak for authenticated users | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-42q3-f5fp-gpxr ** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value. | 1% Низкий | почти 4 года назад | ||
GHSA-42q2-w7pp-mx38 sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files. | 0% Низкий | почти 4 года назад | ||
GHSA-42q2-m54f-jh95 sememos/memos vulnerable to Improper Handling of Values | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-42px-vp8x-r9wx The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-42pv-rvjf-mxph D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-42pr-hpj6-p97q The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-42pq-hf34-5c7v cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243). | CVSS3: 6.3 | 1% Низкий | больше 3 лет назад | |
GHSA-42pq-h6rj-6c6q Memory corruption in Core due to stack-based buffer overflow. | CVSS3: 7.8 | 4% Низкий | около 3 лет назад | |
GHSA-42pq-634r-jghr bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | CVSS3: 9.8 | 33% Средний | больше 2 лет назад | |
GHSA-42pp-ccmj-xrg8 The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files. | 0% Низкий | больше 3 лет назад | ||
GHSA-42pm-gg43-38gr XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-42pj-96jc-q58w In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim. | 0% Низкий | около 4 лет назад | ||
GHSA-42pj-35w6-4jwg A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges. | CVSS3: 7 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу