Количество 314 458
Количество 314 458
GHSA-3x4g-gq53-pcx7
Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.
GHSA-3x4g-4374-v83h
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
GHSA-3x4f-24vq-5mhp
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3x4c-pq33-4w3q
Improper authorisation of members discloses room membership to non-members
GHSA-3x49-p9xf-cg52
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
GHSA-3x49-h2mv-h459
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
GHSA-3x49-g6rc-c284
LiteDB may deserialize bad JSON on object type using _type
GHSA-3x48-c5fq-3p9x
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.
GHSA-3x48-6948-gjj7
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
GHSA-3x47-w4rx-6pm7
LoLLMS Path Traversal vulnerability
GHSA-3x47-pxw6-fmvq
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.
GHSA-3x47-j85r-45r9
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
GHSA-3x47-hh2w-gf29
Rejected reason: Not used
GHSA-3x46-vw5g-qxj4
Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.
GHSA-3x46-hg82-953f
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
GHSA-3x46-fhq4-2cp2
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
GHSA-3x46-c2g7-344x
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
GHSA-3x46-6xw6-vv9h
Rejected reason: Not used
GHSA-3x46-395m-v3qc
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
GHSA-3x46-2jq5-628v
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x4g-gq53-pcx7 Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php. | 1% Низкий | почти 4 года назад | ||
GHSA-3x4g-4374-v83h there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 4.4 | 0% Низкий | больше 1 года назад | |
GHSA-3x4f-24vq-5mhp Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-3x4c-pq33-4w3q Improper authorisation of members discloses room membership to non-members | CVSS3: 3.1 | 0% Низкий | больше 4 лет назад | |
GHSA-3x49-p9xf-cg52 Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables. | 0% Низкий | почти 4 года назад | ||
GHSA-3x49-h2mv-h459 Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-3x49-g6rc-c284 LiteDB may deserialize bad JSON on object type using _type | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-3x48-c5fq-3p9x The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-3x48-6948-gjj7 Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs." | 11% Средний | почти 4 года назад | ||
GHSA-3x47-w4rx-6pm7 LoLLMS Path Traversal vulnerability | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-3x47-pxw6-fmvq Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-3x47-j85r-45r9 Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-3x47-hh2w-gf29 Rejected reason: Not used | около 1 месяца назад | |||
GHSA-3x46-vw5g-qxj4 Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb. | 0% Низкий | почти 4 года назад | ||
GHSA-3x46-hg82-953f A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3x46-fhq4-2cp2 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-3x46-c2g7-344x F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | CVSS3: 8.8 | 19% Средний | почти 2 года назад | |
GHSA-3x46-6xw6-vv9h Rejected reason: Not used | около 1 месяца назад | |||
GHSA-3x46-395m-v3qc Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135. | CVSS3: 3.1 | 0% Низкий | почти 3 года назад | |
GHSA-3x46-2jq5-628v Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776. | 47% Средний | больше 3 лет назад |
Уязвимостей на страницу