Количество 288 099
Количество 288 099
GHSA-23xv-rh65-95rq
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-23xv-3xmf-w354
Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).
GHSA-23xr-9xxr-vg3c
Improper authorization vulnerability in Jenkins Mesos Plugin
GHSA-23xp-j737-282v
Path Traversal in takeapeek
GHSA-23xp-gwgx-qmr4
The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385.
GHSA-23xp-c8gg-3439
The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
GHSA-23xp-397m-q9rx
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.
GHSA-23xm-cf42-h7f9
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function mptcp_limit_get_set of the file ip/ipmptcp.c of the component iproute2. The manipulation leads to memory leak. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-211362 is the identifier assigned to this vulnerability.
GHSA-23xm-3rwj-r45h
Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.
GHSA-23xj-w5qm-57j6
Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
GHSA-23xh-x244-cxmg
Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure.
GHSA-23xh-3w4x-5qh2
Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.
GHSA-23xg-w5j8-3ff2
An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs.
GHSA-23xg-g252-mcgr
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.
GHSA-23xf-wg9r-49fr
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
GHSA-23xf-gc3r-v6rr
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.
GHSA-23xf-5535-62v5
jeecg-boot vulnerable to SQL injection
GHSA-23x9-mmjc-x474
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
GHSA-23x9-8hxr-978c
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
GHSA-23x9-2qmf-qr95
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-23xv-rh65-95rq SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-23xv-3xmf-w354 Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument). | 0% Низкий | больше 3 лет назад | ||
GHSA-23xr-9xxr-vg3c Improper authorization vulnerability in Jenkins Mesos Plugin | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-23xp-j737-282v Path Traversal in takeapeek | CVSS3: 5.3 | 0% Низкий | почти 7 лет назад | |
GHSA-23xp-gwgx-qmr4 The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385. | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
GHSA-23xp-c8gg-3439 The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-23xp-397m-q9rx The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form. | 7% Низкий | больше 3 лет назад | ||
GHSA-23xm-cf42-h7f9 A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function mptcp_limit_get_set of the file ip/ipmptcp.c of the component iproute2. The manipulation leads to memory leak. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-211362 is the identifier assigned to this vulnerability. | CVSS3: 5.5 | почти 3 года назад | ||
GHSA-23xm-3rwj-r45h Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat. | 0% Низкий | около 3 лет назад | ||
GHSA-23xj-w5qm-57j6 Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-23xh-x244-cxmg Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure. | 0% Низкий | около 3 лет назад | ||
GHSA-23xh-3w4x-5qh2 Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-23xg-w5j8-3ff2 An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs. | 0% Низкий | около 3 лет назад | ||
GHSA-23xg-g252-mcgr SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php. | 0% Низкий | больше 3 лет назад | ||
GHSA-23xf-wg9r-49fr The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app. | CVSS3: 9.8 | 94% Критический | около 3 лет назад | |
GHSA-23xf-gc3r-v6rr A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-23xf-5535-62v5 jeecg-boot vulnerable to SQL injection | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-23x9-mmjc-x474 Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941. | 35% Средний | больше 3 лет назад | ||
GHSA-23x9-8hxr-978c OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-23x9-2qmf-qr95 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4. | CVSS3: 6.5 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу