Количество 314 458
Количество 314 458
GHSA-3x7g-rh72-3g94
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-3x7c-c6rj-mhq6
A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 62cb99755243c9c38e4c060c5d8d0e158fe8cdd5. It is recommended to apply a patch to fix this issue.
GHSA-3x7c-249g-p329
A version of rusers is running that exposes valid user information to any entity on the network.
GHSA-3x79-rfwc-8cjp
Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local
GHSA-3x79-3x7f-qrvm
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
GHSA-3x79-282m-jh8f
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.
GHSA-3x78-vqmp-hr8w
Directory traversal vulnerability in the web interface in the Health Monitor service in MatrikonOPC A&E Historian 1.0.0.0 allows remote attackers to read and delete arbitrary files via a crafted URL.
GHSA-3x78-7j32-qc4w
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
GHSA-3x77-v8f7-wp2v
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
GHSA-3x77-qmhw-v3hg
p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.
GHSA-3x77-52mc-3mpg
Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-3x76-j3jj-439j
MoinMoin Cross-site Scripting (XSS) vulnerability
GHSA-3x76-36rv-8v95
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.
GHSA-3x74-wgfj-fp94
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).
GHSA-3x74-v64j-qc3f
Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability
GHSA-3x74-43v8-rvp5
In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.
GHSA-3x73-wm98-jh2g
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
GHSA-3x73-qc77-ff3v
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.
GHSA-3x73-p8v6-p37w
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
GHSA-3x73-p3qx-cwqw
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x7g-rh72-3g94 Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-3x7c-c6rj-mhq6 A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 62cb99755243c9c38e4c060c5d8d0e158fe8cdd5. It is recommended to apply a patch to fix this issue. | CVSS3: 5.3 | 0% Низкий | 8 месяцев назад | |
GHSA-3x7c-249g-p329 A version of rusers is running that exposes valid user information to any entity on the network. | 1% Низкий | почти 4 года назад | ||
GHSA-3x79-rfwc-8cjp Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local | 0% Низкий | больше 3 лет назад | ||
GHSA-3x79-3x7f-qrvm Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12. | 1% Низкий | около 4 лет назад | ||
GHSA-3x79-282m-jh8f The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user. | CVSS3: 4.3 | 0% Низкий | 23 дня назад | |
GHSA-3x78-vqmp-hr8w Directory traversal vulnerability in the web interface in the Health Monitor service in MatrikonOPC A&E Historian 1.0.0.0 allows remote attackers to read and delete arbitrary files via a crafted URL. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x78-7j32-qc4w kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x77-v8f7-wp2v Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-3x77-qmhw-v3hg p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x77-52mc-3mpg Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-3x76-j3jj-439j MoinMoin Cross-site Scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3x76-36rv-8v95 In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108. | CVSS3: 4.2 | 0% Низкий | больше 2 лет назад | |
GHSA-3x74-wgfj-fp94 An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020). | 0% Низкий | больше 3 лет назад | ||
GHSA-3x74-v64j-qc3f Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability | CVSS3: 7.2 | 4% Низкий | больше 2 лет назад | |
GHSA-3x74-43v8-rvp5 In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3x73-wm98-jh2g Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x73-qc77-ff3v Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions. | CVSS3: 6.1 | 0% Низкий | почти 3 года назад | |
GHSA-3x73-p8v6-p37w A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3x73-p3qx-cwqw ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу