Количество 314 458
Количество 314 458
GHSA-3mj9-c62w-jw5w
HTTP Protocol Stack Remote Code Execution Vulnerability
GHSA-3mj9-8h4m-j8f7
Server-Side Request Forgery (SSRF) in kubeflow/kubeflow
GHSA-3mj8-x4jc-gf23
Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
GHSA-3mj8-wjf2-5v9c
HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.
GHSA-3mj8-v2cx-7x5g
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
GHSA-3mj8-5fpc-8c72
Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
GHSA-3mj8-3cm6-5whc
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
GHSA-3mj6-p6q9-4j76
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
GHSA-3mj6-hq84-85g9
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
GHSA-3mj5-5ph7-ggjq
Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.
GHSA-3mj4-w4vq-39pp
Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.
GHSA-3mj4-2258-cj4p
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.
GHSA-3mj3-396v-7f8p
Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
GHSA-3mj2-f6g2-rqg9
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to arbitrary regions of memory, the user may utilize this vector to alter module executable code.
GHSA-3mj2-6x39-pq7w
Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file.
GHSA-3mhx-94rj-7j37
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.
GHSA-3mhx-4cwj-8prc
The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
GHSA-3mhw-mxm8-w9rh
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
GHSA-3mhw-f79r-crmm
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
GHSA-3mhv-6x8q-5v9p
Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through 0.3.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mj9-c62w-jw5w HTTP Protocol Stack Remote Code Execution Vulnerability | CVSS3: 9.8 | 93% Критический | больше 3 лет назад | |
GHSA-3mj9-8h4m-j8f7 Server-Side Request Forgery (SSRF) in kubeflow/kubeflow | CVSS3: 7.7 | 0% Низкий | около 2 лет назад | |
GHSA-3mj8-x4jc-gf23 Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | 2% Низкий | больше 3 лет назад | ||
GHSA-3mj8-wjf2-5v9c HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi. | 0% Низкий | почти 4 года назад | ||
GHSA-3mj8-v2cx-7x5g An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account. | 18% Средний | больше 3 лет назад | ||
GHSA-3mj8-5fpc-8c72 Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-3mj8-3cm6-5whc openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mj6-p6q9-4j76 Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3mj6-hq84-85g9 Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | CVSS3: 5.9 | 0% Низкий | около 2 лет назад | |
GHSA-3mj5-5ph7-ggjq Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-3mj4-w4vq-39pp Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE. | CVSS3: 3.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3mj4-2258-cj4p Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mj3-396v-7f8p Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-3mj2-f6g2-rqg9 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to arbitrary regions of memory, the user may utilize this vector to alter module executable code. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3mj2-6x39-pq7w Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file. | 9% Низкий | больше 3 лет назад | ||
GHSA-3mhx-94rj-7j37 An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3mhx-4cwj-8prc The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3mhw-mxm8-w9rh Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mhw-f79r-crmm An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-3mhv-6x8q-5v9p Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through 0.3.3. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу