Количество 292 001
Количество 292 001
GHSA-2hw7-mxvj-m455
Path traversal in Node-RED-Dashboard
GHSA-2hw7-5qc9-q2cg
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
GHSA-2hw7-485w-9j23
WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.
GHSA-2hw6-6rgf-726v
Moodle XSS Vulnerability
GHSA-2hw6-6573-fv43
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7.
GHSA-2hw6-4rv9-82fp
Uvdesk remote code execution vulnerability
GHSA-2hw5-wx32-97v6
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.
GHSA-2hw5-388c-g7xj
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
GHSA-2hw3-wmq2-hxf7
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
GHSA-2hw3-h8qx-hqqp
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
GHSA-2hw3-28v7-q78p
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
GHSA-2hw2-h3mf-c2j9
Moodle open redirect vulnerability
GHSA-2hw2-7jq8-w9vp
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
GHSA-2hw2-62cp-p9p7
Access control bypass in Apache ZooKeeper
GHSA-2hvx-m86j-h9m3
Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.
GHSA-2hvx-9r8j-qvph
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-2hvx-93c2-p928
** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.
GHSA-2hvw-r4rp-mjpp
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
GHSA-2hvv-h4pw-wcm2
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
GHSA-2hvr-h6gw-qrxp
Cargo extracting malicious crates can fill the file system
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-2hw7-mxvj-m455 Path traversal in Node-RED-Dashboard | 89% Высокий | больше 4 лет назад | ||
GHSA-2hw7-5qc9-q2cg Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg. | 2% Низкий | больше 3 лет назад | ||
GHSA-2hw7-485w-9j23 WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability. | 0% Низкий | больше 3 лет назад | ||
GHSA-2hw6-6rgf-726v Moodle XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw6-6573-fv43 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7. | CVSS3: 6.5 | 0% Низкий | 4 дня назад | |
GHSA-2hw6-4rv9-82fp Uvdesk remote code execution vulnerability | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2hw5-wx32-97v6 Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page. | 2% Низкий | больше 3 лет назад | ||
GHSA-2hw5-388c-g7xj Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw3-wmq2-hxf7 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw3-h8qx-hqqp OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-2hw3-28v7-q78p Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability." | 48% Средний | больше 3 лет назад | ||
GHSA-2hw2-h3mf-c2j9 Moodle open redirect vulnerability | CVSS3: 7.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2hw2-7jq8-w9vp The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | 70% Средний | больше 3 лет назад | ||
GHSA-2hw2-62cp-p9p7 Access control bypass in Apache ZooKeeper | CVSS3: 5.9 | 0% Низкий | больше 6 лет назад | |
GHSA-2hvx-m86j-h9m3 Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function. | 13% Средний | больше 3 лет назад | ||
GHSA-2hvx-9r8j-qvph The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-2hvx-93c2-p928 ** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity. | CVSS3: 8.6 | 0% Низкий | почти 2 года назад | |
GHSA-2hvw-r4rp-mjpp Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. | CVSS3: 5.9 | 1% Низкий | около 2 лет назад | |
GHSA-2hvv-h4pw-wcm2 The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands. | 0% Низкий | больше 3 лет назад | ||
GHSA-2hvr-h6gw-qrxp Cargo extracting malicious crates can fill the file system | CVSS3: 4.2 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу