Количество 282 974
Количество 282 974
GHSA-226m-fqfj-v6xp
Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.
GHSA-226j-3v4h-8cg4
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
GHSA-226h-qrg4-8236
Stored XSS vulnerability in chosen-views-tabbar Plugin
GHSA-226h-j848-vv7w
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-226h-h99r-j24r
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-226h-772w-v9vj
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).
GHSA-226h-2qfh-4hf8
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
GHSA-226c-wpq4-r9cj
SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
GHSA-2269-968q-6hcq
Memory corruption due to improper access control in Qualcomm IPC.
GHSA-2268-w43v-j544
Cross-Site Request Forgery (CSRF) in stitionai/devika
GHSA-2268-rqjm-gx38
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
GHSA-2268-hc24-w7pm
Azure Network Watcher Agent Security Feature Bypass Vulnerability.
GHSA-2268-98wh-qfhf
JLine vulnerable to out of memory error
GHSA-2268-76c3-x85m
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
GHSA-2267-x99j-hcv3
Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.
GHSA-2267-87gq-vw4p
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
GHSA-2267-86vq-8f86
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
GHSA-2266-6m7r-fxww
Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1.
GHSA-2264-q7fx-w4x7
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.
GHSA-2264-54r3-3rjm
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-226m-fqfj-v6xp Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-226j-3v4h-8cg4 Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | CVSS3: 7.1 | 0% Низкий | 8 месяцев назад | |
GHSA-226h-qrg4-8236 Stored XSS vulnerability in chosen-views-tabbar Plugin | CVSS3: 8 | 0% Низкий | около 3 лет назад | |
GHSA-226h-j848-vv7w A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | 19 дней назад | |
GHSA-226h-h99r-j24r Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-226h-772w-v9vj Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address). | 2% Низкий | около 3 лет назад | ||
GHSA-226h-2qfh-4hf8 Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | CVSS3: 9.8 | 0% Низкий | 10 месяцев назад | |
GHSA-226c-wpq4-r9cj SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 0% Низкий | около 3 лет назад | ||
GHSA-2269-968q-6hcq Memory corruption due to improper access control in Qualcomm IPC. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2268-w43v-j544 Cross-Site Request Forgery (CSRF) in stitionai/devika | CVSS3: 8.8 | 12 месяцев назад | ||
GHSA-2268-rqjm-gx38 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. | CVSS3: 5.1 | 0% Низкий | почти 2 года назад | |
GHSA-2268-hc24-w7pm Azure Network Watcher Agent Security Feature Bypass Vulnerability. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2268-98wh-qfhf JLine vulnerable to out of memory error | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2268-76c3-x85m An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-2267-x99j-hcv3 Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-2267-87gq-vw4p In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203 | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2267-86vq-8f86 A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2266-6m7r-fxww Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1. | 0% Низкий | почти 3 года назад | ||
GHSA-2264-q7fx-w4x7 Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script. | 64% Средний | около 3 лет назад | ||
GHSA-2264-54r3-3rjm A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695. | 20% Средний | около 3 лет назад |
Уязвимостей на страницу