Количество 312 573
Количество 312 573
GHSA-3jg2-8xp4-m2fx
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.
GHSA-3jfx-wr2q-r8gh
A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-3jfx-5w5g-hfh9
Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block.
GHSA-3jfw-v39g-268j
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
GHSA-3jfw-8phg-9vp8
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA-3jfw-7g32-85w8
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
GHSA-3jfw-6cv8-rr6m
Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.
GHSA-3jfv-rhc4-5hmj
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
GHSA-3jfr-j9w4-px6x
In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
GHSA-3jfr-38pr-8j88
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
GHSA-3jfq-x5rf-pxwc
SQL Server Native Client Remote Code Execution Vulnerability
GHSA-3jfq-h25g-xqjx
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
GHSA-3jfq-8hwm-x9j5
Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends."
GHSA-3jfq-742w-xg8j
Users with any cluster secret update access may update out-of-bounds cluster secrets
GHSA-3jfq-4f5c-mp6v
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
GHSA-3jfq-3r5r-8hmh
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
GHSA-3jfj-w7p2-fccc
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-3jfh-c76q-4r5j
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
GHSA-3jfh-7px5-vr77
SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3jg2-8xp4-m2fx Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-3jfx-wr2q-r8gh A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | 7 месяцев назад | |
GHSA-3jfx-5w5g-hfh9 Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block. | 29% Средний | почти 4 года назад | ||
GHSA-3jfw-v39g-268j Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding. | 0% Низкий | больше 3 лет назад | ||
GHSA-3jfw-8phg-9vp8 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 4.9 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfw-7g32-85w8 The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | 1% Низкий | больше 3 лет назад | ||
GHSA-3jfw-6cv8-rr6m Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-3jfv-rhc4-5hmj Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3jfr-j9w4-px6x In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-3jfr-38pr-8j88 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfq-x5rf-pxwc SQL Server Native Client Remote Code Execution Vulnerability | CVSS3: 8.8 | 4% Низкий | около 1 года назад | |
GHSA-3jfq-h25g-xqjx Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution. | CVSS3: 9.8 | 0% Низкий | 18 дней назад | |
GHSA-3jfq-g458-7qm9 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization | CVSS3: 8.2 | 86% Высокий | больше 4 лет назад | |
GHSA-3jfq-8hwm-x9j5 Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends." | 1% Низкий | почти 4 года назад | ||
GHSA-3jfq-742w-xg8j Users with any cluster secret update access may update out-of-bounds cluster secrets | CVSS3: 9.1 | 0% Низкий | почти 3 года назад | |
GHSA-3jfq-4f5c-mp6v RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept. | CVSS3: 9.8 | 4% Низкий | около 1 года назад | |
GHSA-3jfq-3r5r-8hmh SQL injection exists in LaiKetui v3.5.0 the background administrator list. | CVSS3: 7.2 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfj-w7p2-fccc Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-3jfh-c76q-4r5j In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfh-7px5-vr77 SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу