Количество 314 458
Количество 314 458
GHSA-3vf5-xm2p-6mh5
Cockpit Cross-site Scripting vulnerability
GHSA-3vf5-m872-p593
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, a buffer overflow can occur in SafeSwitch.
GHSA-3vf5-967m-jfcw
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.
GHSA-3vf4-qf7v-8hwx
Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
GHSA-3vf4-p6xq-xxr9
The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.
GHSA-3vf4-6xfg-p852
cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).
GHSA-3vf4-2h3f-crc2
IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.
GHSA-3vf3-j8cr-x4g6
The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
GHSA-3vf3-8x3v-cfhr
In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3vf2-rf9c-6455
Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3vf2-r6qr-hcf2
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
GHSA-3vf2-6fxh-3q3m
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."
GHSA-3vcx-x6r7-phpm
SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
GHSA-3vcx-wp2w-x68x
Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2.
GHSA-3vcx-w94h-68vg
XXE vulnerability in Jenkins Android Lint Plugin
GHSA-3vcx-qq88-36qg
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
GHSA-3vcw-xhqc-97mh
Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private network connection to securely download updates. The product does not verify it is still connected to this virtual private network before downloading updates. An attacker with local network access to the programmer could influence these communications.
GHSA-3vcw-92x2-jjg4
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.
GHSA-3vcv-r276-ff59
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
GHSA-3vcv-qvpj-9v53
SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3vf5-xm2p-6mh5 Cockpit Cross-site Scripting vulnerability | CVSS3: 8.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3vf5-m872-p593 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, a buffer overflow can occur in SafeSwitch. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3vf5-967m-jfcw A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests. | CVSS3: 9.1 | 0% Низкий | 12 месяцев назад | |
GHSA-3vf4-qf7v-8hwx Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory. | CVSS3: 4 | 0% Низкий | больше 1 года назад | |
GHSA-3vf4-p6xq-xxr9 The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error. | 1% Низкий | больше 3 лет назад | ||
GHSA-3vf4-6xfg-p852 cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184). | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3vf4-2h3f-crc2 IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-3vf3-j8cr-x4g6 The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | CVSS3: 6.5 | 79% Высокий | больше 1 года назад | |
GHSA-3vf3-8x3v-cfhr In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
GHSA-3vf2-rf9c-6455 Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-3vf2-r6qr-hcf2 Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3vf2-6fxh-3q3m WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability." | CVSS3: 7.5 | 24% Средний | больше 3 лет назад | |
GHSA-3vcx-x6r7-phpm SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | 2% Низкий | почти 4 года назад | ||
GHSA-3vcx-wp2w-x68x Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-3vcx-w94h-68vg XXE vulnerability in Jenkins Android Lint Plugin | CVSS3: 8.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3vcx-qq88-36qg The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | CVSS3: 9.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3vcw-xhqc-97mh Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private network connection to securely download updates. The product does not verify it is still connected to this virtual private network before downloading updates. An attacker with local network access to the programmer could influence these communications. | CVSS3: 8 | 0% Низкий | больше 3 лет назад | |
GHSA-3vcw-92x2-jjg4 A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges. | CVSS3: 6 | 0% Низкий | больше 3 лет назад | |
GHSA-3vcv-r276-ff59 Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-3vcv-qvpj-9v53 SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу