Количество 314 212
Количество 314 212
GHSA-3x47-pxw6-fmvq
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.
GHSA-3x47-j85r-45r9
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
GHSA-3x47-hh2w-gf29
Rejected reason: Not used
GHSA-3x46-vw5g-qxj4
Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.
GHSA-3x46-hg82-953f
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
GHSA-3x46-fhq4-2cp2
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
GHSA-3x46-c2g7-344x
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
GHSA-3x46-6xw6-vv9h
Rejected reason: Not used
GHSA-3x46-395m-v3qc
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
GHSA-3x46-2jq5-628v
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.
GHSA-3x45-j72c-xqpj
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
GHSA-3x44-c8w2-mxwg
The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.
GHSA-3x44-884c-cc67
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
GHSA-3x43-9cxq-4fwr
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
GHSA-3x43-8h7p-m97w
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.
GHSA-3x42-vgc3-7f6c
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
GHSA-3x3x-vjcr-56cc
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
GHSA-3x3x-gvp4-q59h
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
GHSA-3x3x-fgf2-hxxv
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.
GHSA-3x3w-vcjx-7796
Cross-Site Request Forgery in easyii CMS
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x47-pxw6-fmvq Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-3x47-j85r-45r9 Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-3x47-hh2w-gf29 Rejected reason: Not used | около 1 месяца назад | |||
GHSA-3x46-vw5g-qxj4 Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb. | 0% Низкий | почти 4 года назад | ||
GHSA-3x46-hg82-953f A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3x46-fhq4-2cp2 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-3x46-c2g7-344x F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | CVSS3: 8.8 | 19% Средний | почти 2 года назад | |
GHSA-3x46-6xw6-vv9h Rejected reason: Not used | около 1 месяца назад | |||
GHSA-3x46-395m-v3qc Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135. | CVSS3: 3.1 | 0% Низкий | почти 3 года назад | |
GHSA-3x46-2jq5-628v Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776. | 47% Средний | больше 3 лет назад | ||
GHSA-3x45-j72c-xqpj Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-3x44-c8w2-mxwg The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request. | CVSS3: 6 | 0% Низкий | больше 3 лет назад | |
GHSA-3x44-884c-cc67 PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3x43-9cxq-4fwr The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294. | 5% Низкий | почти 4 года назад | ||
GHSA-3x43-8h7p-m97w IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3x42-vgc3-7f6c An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability. | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад | |
GHSA-3x3x-vjcr-56cc The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3x3x-gvp4-q59h SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x3x-fgf2-hxxv Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security. | 1% Низкий | больше 3 лет назад | ||
GHSA-3x3w-vcjx-7796 Cross-Site Request Forgery in easyii CMS | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу