Количество 314 458
Количество 314 458
GHSA-3p87-w3c5-27gf
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
GHSA-3p87-gqw8-4pf2
Showdoc CSRF Vulnerability
GHSA-3p87-8mrf-82ww
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
GHSA-3p86-xgrq-m6p6
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
GHSA-3p86-mc6x-347c
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
GHSA-3p86-9fpc-5qvc
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
GHSA-3p86-9955-h393
Arbitrary File Overwrite in Eclipse JGit
GHSA-3p85-p4qg-hcrp
pimcore is vulnerable to Cross-site Scripting
GHSA-3p85-44fv-28jc
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
GHSA-3p82-g7cx-7qrf
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-3p82-57h4-gc59
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
GHSA-3p7x-pg2q-x6w8
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.
GHSA-3p7x-m58j-fm72
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).
GHSA-3p7x-94q9-jq9x
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
GHSA-3p7w-fr8h-8fxc
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions.
GHSA-3p7v-r2rf-xx9x
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions.
GHSA-3p7v-c8pg-528c
Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.
GHSA-3p7v-5rxq-8fw3
Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through 1.14.
GHSA-3p7v-42w7-qvff
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
GHSA-3p7r-h3vx-2qj9
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3p87-w3c5-27gf phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save | 0% Низкий | больше 3 лет назад | ||
GHSA-3p87-gqw8-4pf2 Showdoc CSRF Vulnerability | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3p87-8mrf-82ww In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will. | CVSS3: 3.5 | 0% Низкий | 3 месяца назад | |
GHSA-3p86-xgrq-m6p6 Improper Neutralization of Input During Web Page Generation in Apache Tomcat | 26% Средний | почти 4 года назад | ||
GHSA-3p86-mc6x-347c An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-3p86-9fpc-5qvc WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1. | 2% Низкий | больше 3 лет назад | ||
GHSA-3p86-9955-h393 Arbitrary File Overwrite in Eclipse JGit | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3p85-p4qg-hcrp pimcore is vulnerable to Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | около 4 лет назад | |
GHSA-3p85-44fv-28jc Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3p82-g7cx-7qrf A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 9 месяцев назад | |
GHSA-3p82-57h4-gc59 ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions. | CVSS3: 8.8 | 4% Низкий | больше 3 лет назад | |
GHSA-3p7x-pg2q-x6w8 The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import. | CVSS3: 9 | 0% Низкий | больше 3 лет назад | |
GHSA-3p7x-m58j-fm72 Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML). | 0% Низкий | больше 3 лет назад | ||
GHSA-3p7x-94q9-jq9x pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability | CVSS3: 7.4 | 0% Низкий | 3 дня назад | |
GHSA-3p7w-fr8h-8fxc The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. | 1% Низкий | больше 3 лет назад | ||
GHSA-3p7v-r2rf-xx9x Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-3p7v-c8pg-528c Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters. | 0% Низкий | почти 4 года назад | ||
GHSA-3p7v-5rxq-8fw3 Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through 1.14. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-3p7v-42w7-qvff Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992. | 3% Низкий | больше 3 лет назад | ||
GHSA-3p7r-h3vx-2qj9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3. | CVSS3: 9.3 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу