Количество 314 458
Количество 314 458
GHSA-3r26-7xv7-xpjf
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-3r24-qx7j-4fr4
The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-3r23-64c4-mj87
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-3r22-jvx3-7mjc
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)
GHSA-3qxw-r9qq-5f2p
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through <= 2.4.4.
GHSA-3qxw-7f8c-wvj7
The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656.
GHSA-3qxv-v5fx-gc4p
Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.
GHSA-3qxv-gfg4-4cc8
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
GHSA-3qxv-8pqm-xqw3
** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker.
GHSA-3qxr-q72q-hmwp
Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)
GHSA-3qxr-h63q-m7x3
An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.
GHSA-3qxr-cm3w-hpmq
The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
GHSA-3qxr-9jgv-5jfg
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.
GHSA-3qxr-2r44-6w45
An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.
GHSA-3qxq-rx8j-qpmj
Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.
GHSA-3qxq-qwff-776p
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Online Help.
GHSA-3qxq-5jcx-g5cg
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action.
GHSA-3qxq-4rfh-fpmx
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
GHSA-3qxp-wv2v-jfc4
.NET Framework Denial of Service Vulnerability
GHSA-3qxp-qjq7-w4hf
CHECK-fail in tf.raw_ops.EncodePng
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3r26-7xv7-xpjf Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | около 1 месяца назад | |||
GHSA-3r24-qx7j-4fr4 The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 7 месяцев назад | |
GHSA-3r23-64c4-mj87 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-3r22-jvx3-7mjc A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior) | CVSS3: 6.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3qxw-r9qq-5f2p Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through <= 2.4.4. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-3qxw-7f8c-wvj7 The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656. | 1% Низкий | почти 4 года назад | ||
GHSA-3qxv-v5fx-gc4p Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file. | 1% Низкий | почти 4 года назад | ||
GHSA-3qxv-gfg4-4cc8 In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3qxv-8pqm-xqw3 ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker. | 2% Низкий | почти 4 года назад | ||
GHSA-3qxr-q72q-hmwp Jenkins CI Game Plugin allows Cross-Site Scripting (XSS) | CVSS3: 6.1 | 2% Низкий | почти 4 года назад | |
GHSA-3qxr-h63q-m7x3 An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3qxr-cm3w-hpmq The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | CVSS3: 4.4 | 0% Низкий | около 2 лет назад | |
GHSA-3qxr-9jgv-5jfg mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges. | 2% Низкий | почти 4 года назад | ||
GHSA-3qxr-2r44-6w45 An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-3qxq-rx8j-qpmj Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags. | 0% Низкий | почти 4 года назад | ||
GHSA-3qxq-qwff-776p Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Online Help. | 0% Низкий | больше 3 лет назад | ||
GHSA-3qxq-5jcx-g5cg SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time parameter in a get action. | 0% Низкий | больше 3 лет назад | ||
GHSA-3qxq-4rfh-fpmx An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. | 0% Низкий | почти 4 года назад | ||
GHSA-3qxp-wv2v-jfc4 .NET Framework Denial of Service Vulnerability | CVSS3: 7.5 | 6% Низкий | около 2 лет назад | |
GHSA-3qxp-qjq7-w4hf CHECK-fail in tf.raw_ops.EncodePng | CVSS3: 2.5 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу