Количество 288 099
Количество 288 099
GHSA-232q-w9mq-2c55
The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
GHSA-232q-v7rp-6ff8
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
GHSA-232p-vwff-86mp
Docker Swarm encrypted overlay network may be unauthenticated
GHSA-232p-m442-j9m4
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.
GHSA-232p-99pf-h332
Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.
GHSA-232p-59mg-f98p
Microweber Cross-site Scripting can result in redirection to a malicious site
GHSA-232m-xvr4-2347
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.
GHSA-232m-53gr-9v22
The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.
GHSA-232g-vj6v-88w6
An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.
GHSA-232g-h7w4-2pxj
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.
GHSA-232f-9f2g-m34q
Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.
GHSA-232f-8fc5-f649
Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."
GHSA-232f-66gw-9wfc
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
GHSA-2328-vc59-64q8
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.
GHSA-2328-876m-g2rg
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
GHSA-2327-m5w2-rg7f
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."
GHSA-2326-xfc9-g293
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.
GHSA-2326-pfpj-vx3h
lexical-core has multiple soundness issues
GHSA-2326-hx7g-3m9r
Apache MINA SSHD: integrity check bypass
GHSA-2326-85qm-8gr9
Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-232q-w9mq-2c55 The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-232q-v7rp-6ff8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003. | CVSS3: 8.8 | 0% Низкий | 11 месяцев назад | |
GHSA-232p-vwff-86mp Docker Swarm encrypted overlay network may be unauthenticated | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-232p-m442-j9m4 In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this. | 0% Низкий | 5 месяцев назад | ||
GHSA-232p-99pf-h332 Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-232p-59mg-f98p Microweber Cross-site Scripting can result in redirection to a malicious site | CVSS3: 6.1 | 16% Средний | почти 3 года назад | |
GHSA-232m-xvr4-2347 A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-232m-53gr-9v22 The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages. | 0% Низкий | больше 3 лет назад | ||
GHSA-232g-vj6v-88w6 An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-232g-h7w4-2pxj Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-232f-9f2g-m34q Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application. | 1% Низкий | больше 3 лет назад | ||
GHSA-232f-8fc5-f649 Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation." | 0% Низкий | больше 3 лет назад | ||
GHSA-232f-66gw-9wfc A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query. | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-2328-vc59-64q8 The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header. | 1% Низкий | около 3 лет назад | ||
GHSA-2328-876m-g2rg In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-2327-m5w2-rg7f The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak." | 2% Низкий | больше 3 лет назад | ||
GHSA-2326-xfc9-g293 SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter. | 1% Низкий | около 3 лет назад | ||
GHSA-2326-pfpj-vx3h lexical-core has multiple soundness issues | 11 месяцев назад | |||
GHSA-2326-hx7g-3m9r Apache MINA SSHD: integrity check bypass | CVSS3: 5.9 | 0% Низкий | 12 месяцев назад | |
GHSA-2326-85qm-8gr9 Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу