Количество 314 458
Количество 314 458
GHSA-3q28-538h-7pqq
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
GHSA-3q27-8g46-2vwm
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
GHSA-3q27-5m93-xfm4
Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access.
GHSA-3q26-rw63-5772
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
GHSA-3q26-f695-pp76
@cyanheads/git-mcp-server vulnerable to command injection in several tools
GHSA-3q25-m4x5-9jh7
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
GHSA-3q24-wf35-56h6
IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.
GHSA-3q24-rrgq-j66h
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
GHSA-3q23-2j2r-mmw3
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
GHSA-3q22-68gw-x3mq
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
GHSA-3pxx-76hx-4rw2
Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.
GHSA-3pxv-j5r5-v5qh
In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...
GHSA-3pxr-vgjw-q3f8
Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
GHSA-3pxr-3j7f-c35j
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
GHSA-3pxq-xg4j-rgqx
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
GHSA-3pxq-5cc9-p3hw
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.
GHSA-3pxq-4mq2-m2mc
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.
GHSA-3pxp-pwrp-2w6f
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.
GHSA-3pxp-6963-46r9
Command Injection in pdfinfojs
GHSA-3pxp-67jr-6qw6
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3q28-538h-7pqq Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. | CVSS3: 4.8 | 0% Низкий | больше 1 года назад | |
GHSA-3q27-8g46-2vwm Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | CVSS3: 9.1 | 1% Низкий | больше 1 года назад | |
GHSA-3q27-5m93-xfm4 Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access. | CVSS3: 8.6 | 0% Низкий | около 1 года назад | |
GHSA-3q26-rw63-5772 There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data. | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
GHSA-3q26-f695-pp76 @cyanheads/git-mcp-server vulnerable to command injection in several tools | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-3q25-m4x5-9jh7 An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users. | 2% Низкий | больше 3 лет назад | ||
GHSA-3q24-wf35-56h6 IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service. | CVSS3: 6 | 0% Низкий | около 1 года назад | |
GHSA-3q24-rrgq-j66h Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. | CVSS3: 5.4 | 5% Низкий | почти 3 года назад | |
GHSA-3q23-2j2r-mmw3 Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | CVSS3: 8.8 | 18% Средний | около 1 года назад | |
GHSA-3q22-68gw-x3mq IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
GHSA-3pxx-76hx-4rw2 Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411. | 0% Низкий | почти 4 года назад | ||
GHSA-3pxv-j5r5-v5qh In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee... | CVSS3: 5.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3pxr-vgjw-q3f8 Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0% Низкий | больше 3 лет назад | ||
GHSA-3pxr-3j7f-c35j Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-3pxq-xg4j-rgqx An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component | CVSS3: 9.8 | 1% Низкий | 10 месяцев назад | |
GHSA-3pxq-5cc9-p3hw Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address. | 1% Низкий | почти 4 года назад | ||
GHSA-3pxq-4mq2-m2mc The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters. | 5% Низкий | больше 3 лет назад | ||
GHSA-3pxp-pwrp-2w6f Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack. | 1% Низкий | почти 4 года назад | ||
GHSA-3pxp-6963-46r9 Command Injection in pdfinfojs | CVSS3: 9.8 | 4% Низкий | больше 7 лет назад | |
GHSA-3pxp-67jr-6qw6 Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу