Количество 314 458
Количество 314 458
GHSA-3w8m-pw3c-4478
admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.
GHSA-3w8h-vhc9-93cj
A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name' parameters during the 'Copy to custom personas folder for editing' process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information.
GHSA-3w8g-xr3f-2mp8
Out of bounds write in nalgebra
GHSA-3w8g-xqh4-qqfx
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.
GHSA-3w8c-pp2g-pw99
myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.
GHSA-3w8c-hmvh-m87g
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.
GHSA-3w8c-ghf8-rmwq
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
GHSA-3w89-xp68-5ffh
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
GHSA-3w89-hgwc-85v8
Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.
GHSA-3w88-gmx5-rx4v
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
GHSA-3w88-854j-p487
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image allows Stored XSS.This issue affects Popup Image: from n/a through 1.0.1.
GHSA-3w87-pggf-mwm8
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783.
GHSA-3w87-fgr4-8m86
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
GHSA-3w87-5jwj-39vh
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.
GHSA-3w86-j9mv-8fpr
images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.
GHSA-3w86-8cj7-m4r5
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).
GHSA-3w85-rr8r-762j
Azure Stack Hub Elevation of Privilege Vulnerability
GHSA-3w85-93xm-x7vx
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
GHSA-3w85-5p9g-h334
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
GHSA-3w84-x2pj-xq9r
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w8m-pw3c-4478 admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211. | 3% Низкий | почти 4 года назад | ||
GHSA-3w8h-vhc9-93cj A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name' parameters during the 'Copy to custom personas folder for editing' process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-3w8g-xr3f-2mp8 Out of bounds write in nalgebra | CVSS3: 9.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3w8g-xqh4-qqfx An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3w8c-pp2g-pw99 myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable. | 29% Средний | почти 4 года назад | ||
GHSA-3w8c-hmvh-m87g Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671. | 59% Средний | почти 4 года назад | ||
GHSA-3w8c-ghf8-rmwq The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3w89-xp68-5ffh A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | 10% Средний | больше 3 лет назад | ||
GHSA-3w89-hgwc-85v8 Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3w88-gmx5-rx4v Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.) | CVSS3: 8.2 | 81% Высокий | больше 3 лет назад | |
GHSA-3w88-854j-p487 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image allows Stored XSS.This issue affects Popup Image: from n/a through 1.0.1. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-3w87-pggf-mwm8 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783. | 1% Низкий | больше 3 лет назад | ||
GHSA-3w87-fgr4-8m86 Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c. | 1% Низкий | больше 3 лет назад | ||
GHSA-3w87-5jwj-39vh USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-3w86-j9mv-8fpr images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames. | 7% Низкий | почти 4 года назад | ||
GHSA-3w86-8cj7-m4r5 A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3). | CVSS3: 9.8 | 6% Низкий | больше 3 лет назад | |
GHSA-3w85-rr8r-762j Azure Stack Hub Elevation of Privilege Vulnerability | CVSS3: 8.2 | 1% Низкий | больше 1 года назад | |
GHSA-3w85-93xm-x7vx mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-3w85-5p9g-h334 Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type | CVSS3: 4.3 | 1% Низкий | 10 месяцев назад | |
GHSA-3w84-x2pj-xq9r Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter. | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу