Количество 314 458
Количество 314 458
GHSA-3jfw-8phg-9vp8
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA-3jfw-7g32-85w8
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
GHSA-3jfw-6cv8-rr6m
Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.
GHSA-3jfv-rhc4-5hmj
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
GHSA-3jfr-j9w4-px6x
In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
GHSA-3jfr-38pr-8j88
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
GHSA-3jfq-x5rf-pxwc
SQL Server Native Client Remote Code Execution Vulnerability
GHSA-3jfq-h25g-xqjx
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
GHSA-3jfq-8hwm-x9j5
Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends."
GHSA-3jfq-742w-xg8j
Users with any cluster secret update access may update out-of-bounds cluster secrets
GHSA-3jfq-4f5c-mp6v
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
GHSA-3jfq-3r5r-8hmh
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
GHSA-3jfj-w7p2-fccc
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-3jfh-c76q-4r5j
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
GHSA-3jfh-7px5-vr77
SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
GHSA-3jfh-77jm-9vg4
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.
GHSA-3jfh-3982-8rhf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Classic Pros And Cons allows Stored XSS.This issue affects Mighty Classic Pros And Cons: from n/a through 2.0.9.
GHSA-3jfg-74jc-hjq4
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.
GHSA-3jff-v2mx-4rwr
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3jfw-8phg-9vp8 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 4.9 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfw-7g32-85w8 The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | 1% Низкий | больше 3 лет назад | ||
GHSA-3jfw-6cv8-rr6m Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-3jfv-rhc4-5hmj Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3jfr-j9w4-px6x In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-3jfr-38pr-8j88 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfq-x5rf-pxwc SQL Server Native Client Remote Code Execution Vulnerability | CVSS3: 8.8 | 4% Низкий | около 1 года назад | |
GHSA-3jfq-h25g-xqjx Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution. | CVSS3: 9.8 | 0% Низкий | 18 дней назад | |
GHSA-3jfq-g458-7qm9 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization | CVSS3: 8.2 | 85% Высокий | больше 4 лет назад | |
GHSA-3jfq-8hwm-x9j5 Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends." | 1% Низкий | почти 4 года назад | ||
GHSA-3jfq-742w-xg8j Users with any cluster secret update access may update out-of-bounds cluster secrets | CVSS3: 9.1 | 0% Низкий | почти 3 года назад | |
GHSA-3jfq-4f5c-mp6v RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept. | CVSS3: 9.8 | 4% Низкий | около 1 года назад | |
GHSA-3jfq-3r5r-8hmh SQL injection exists in LaiKetui v3.5.0 the background administrator list. | CVSS3: 7.2 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfj-w7p2-fccc Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-3jfh-c76q-4r5j In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfh-7px5-vr77 SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76 SAP GUI for Windows (BC-FES-GUI) before versions 7.5, 7.6, and SAP GUI for Java (BC-FES-JAV) before version 7.5, allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3jfh-77jm-9vg4 Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device. | 0% Низкий | больше 3 лет назад | ||
GHSA-3jfh-3982-8rhf Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Classic Pros And Cons allows Stored XSS.This issue affects Mighty Classic Pros And Cons: from n/a through 2.0.9. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-3jfg-74jc-hjq4 A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-3jff-v2mx-4rwr An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу