Количество 314 458
Количество 314 458
GHSA-3m64-v24q-w9wr
Windows DNS Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-33754, CVE-2021-33780, CVE-2021-34494, CVE-2021-34525.
GHSA-3m64-mc9g-274w
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.
GHSA-3m64-79r5-56f2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
GHSA-3m63-4rwc-c6p8
A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-3m5x-qv26-v6mr
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
GHSA-3m5x-89wr-x574
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
GHSA-3m5v-mwj4-jp69
The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the affected site's server which may make remote code execution possible. Note: The required nonce for the vulnerability is in the CubeWP Framework plugin.
GHSA-3m5v-crmw-qqfm
SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-3m5r-wc67-jg8m
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
GHSA-3m5r-vf35-8v65
A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.
GHSA-3m5q-q39v-xf8f
nocodb SQL Injection vulnerability
GHSA-3m5q-4mj3-9362
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.
GHSA-3m5m-x34p-6vq4
memory corruption when an invalid firehose patch command is invoked.
GHSA-3m5j-rg6q-w4gv
SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
GHSA-3m5j-r9wr-wr68
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
GHSA-3m5j-q5c3-cr8m
Monkey's Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file.
GHSA-3m5j-38m5-7239
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
GHSA-3m5h-3839-5w2g
Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.
GHSA-3m5c-7hqx-55x7
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
GHSA-3m59-fh79-m7m6
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3m64-v24q-w9wr Windows DNS Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-33754, CVE-2021-33780, CVE-2021-34494, CVE-2021-34525. | CVSS3: 8 | 8% Низкий | больше 3 лет назад | |
GHSA-3m64-mc9g-274w An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1. | 89% Высокий | больше 3 лет назад | ||
GHSA-3m64-79r5-56f2 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-3m63-4rwc-c6p8 A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-3m5x-qv26-v6mr Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | CVSS3: 6.5 | 7% Низкий | больше 2 лет назад | |
GHSA-3m5x-89wr-x574 The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method. | 0% Низкий | больше 3 лет назад | ||
GHSA-3m5v-mwj4-jp69 The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the affected site's server which may make remote code execution possible. Note: The required nonce for the vulnerability is in the CubeWP Framework plugin. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
GHSA-3m5v-crmw-qqfm SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3m5r-wc67-jg8m Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename. | 5% Низкий | почти 4 года назад | ||
GHSA-3m5r-vf35-8v65 A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file. | 0% Низкий | больше 3 лет назад | ||
GHSA-3m5q-q39v-xf8f nocodb SQL Injection vulnerability | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3m5q-4mj3-9362 pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file. | 0% Низкий | почти 4 года назад | ||
GHSA-3m5m-x34p-6vq4 memory corruption when an invalid firehose patch command is invoked. | CVSS3: 6.8 | 0% Низкий | больше 1 года назад | |
GHSA-3m5j-rg6q-w4gv SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3m5j-r9wr-wr68 The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-3m5j-q5c3-cr8m Monkey's Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file. | 0% Низкий | почти 4 года назад | ||
GHSA-3m5j-38m5-7239 An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications). | 0% Низкий | больше 3 лет назад | ||
GHSA-3m5h-3839-5w2g Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID. | 0% Низкий | почти 4 года назад | ||
GHSA-3m5c-7hqx-55x7 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. | 1% Низкий | больше 3 лет назад | ||
GHSA-3m59-fh79-m7m6 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу