Количество 314 458
Количество 314 458
GHSA-3vcr-vjpj-p33c
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.
GHSA-3vcr-m67m-mr3p
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
GHSA-3vcr-579j-4x48
Stored XSS vulnerability in Jenkins TAP Plugin
GHSA-3vcq-64gh-84x2
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
GHSA-3vcp-r62v-xpvg
Apache DolphinScheduler vulnerable to Alert Script Attack
GHSA-3vcm-c42p-3hhf
Mattermost Missing Authorization vulnerability
GHSA-3vcm-c256-hxfx
Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.
GHSA-3vcm-3w42-g672
Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-3vcj-x75g-g7r9
In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: ALPS07628612.
GHSA-3vcj-crmp-9f49
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.
GHSA-3vcj-cj9g-vfr3
This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.
GHSA-3vcj-6338-x74x
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.
GHSA-3vch-5776-vg3j
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
GHSA-3vcg-jhjm-5ffm
An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.
GHSA-3vcg-j39x-cwfm
Vyper's `slice()` may elide side-effects when output length is 0
GHSA-3vcg-8p79-jpcv
SVGlib Vulnerable to XXE Attacks
GHSA-3vcc-wpcm-9vgm
Unauthenticated attackers can rename "rooms" of arbitrary users.
GHSA-3vcc-qrc9-5rvw
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
GHSA-3vcc-pp2v-7ffr
A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .
GHSA-3vcc-ghcj-6f52
Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3vcr-vjpj-p33c join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters. | 8% Низкий | почти 4 года назад | ||
GHSA-3vcr-m67m-mr3p Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution. | 2% Низкий | почти 4 года назад | ||
GHSA-3vcr-579j-4x48 Stored XSS vulnerability in Jenkins TAP Plugin | CVSS3: 5.4 | 6% Низкий | больше 2 лет назад | |
GHSA-3vcq-64gh-84x2 Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-3vcp-r62v-xpvg Apache DolphinScheduler vulnerable to Alert Script Attack | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
GHSA-3vcm-c42p-3hhf Mattermost Missing Authorization vulnerability | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3vcm-c256-hxfx Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file. | 0% Низкий | больше 3 лет назад | ||
GHSA-3vcm-3w42-g672 Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-3vcj-x75g-g7r9 In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628612; Issue ID: ALPS07628612. | CVSS3: 4.4 | 0% Низкий | почти 3 года назад | |
GHSA-3vcj-crmp-9f49 Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3. | 2% Низкий | почти 4 года назад | ||
GHSA-3vcj-cj9g-vfr3 This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device. | 0% Низкий | 5 месяцев назад | ||
GHSA-3vcj-6338-x74x BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application. | 2% Низкий | почти 4 года назад | ||
GHSA-3vch-5776-vg3j An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3vcg-jhjm-5ffm An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges. | CVSS3: 7.8 | 1% Низкий | 11 месяцев назад | |
GHSA-3vcg-j39x-cwfm Vyper's `slice()` may elide side-effects when output length is 0 | 0% Низкий | 9 месяцев назад | ||
GHSA-3vcg-8p79-jpcv SVGlib Vulnerable to XXE Attacks | CVSS3: 9.8 | 0% Низкий | почти 5 лет назад | |
GHSA-3vcc-wpcm-9vgm Unauthenticated attackers can rename "rooms" of arbitrary users. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-3vcc-qrc9-5rvw Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). | 73% Высокий | больше 3 лет назад | ||
GHSA-3vcc-pp2v-7ffr A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . . | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-3vcc-ghcj-6f52 Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1. | 0% Низкий | 12 дней назад |
Уязвимостей на страницу