Количество 314 458
Количество 314 458
GHSA-3j95-fjv2-3m4p
CSS Injection in Chartkick gem
GHSA-3j95-8g47-fpwh
Mattermost allows team admin user without "Add Team Members" permission to disable invite URL
GHSA-3j95-8976-jfmp
Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally signed firmware updates and is susceptible to processing and installing modified/malicious images.
GHSA-3j95-64vv-272j
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.
GHSA-3j94-c55m-42mx
Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140321-1336 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.12 IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via a crafted report parameter.
GHSA-3j94-8x5f-gpm9
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
GHSA-3j93-7rf7-p7m6
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter
GHSA-3j93-3979-xwwx
Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters.
GHSA-3j8x-8x9q-3m4r
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
GHSA-3j8r-jf9w-5cmh
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
GHSA-3j8r-26jq-jj7w
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
GHSA-3j8q-j2j7-x49c
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-3j8q-2cfg-hm94
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.
GHSA-3j8p-v97g-rq93
An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version of NMC G2 which is available on the Eaton download center.
GHSA-3j8p-q74h-4pxp
There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
GHSA-3j8m-jchc-w7pr
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service.
GHSA-3j8m-4wcj-vrx5
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=read_msg of the component POST Parameter Handler. The manipulation of the argument convo_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230348.
GHSA-3j8g-45hc-8h5f
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.
GHSA-3j8f-xvm3-ffx4
Authorization Bypass in parse-path
GHSA-3j89-v6qj-mgf2
LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3j95-fjv2-3m4p CSS Injection in Chartkick gem | CVSS3: 6.1 | 0% Низкий | больше 5 лет назад | |
GHSA-3j95-8g47-fpwh Mattermost allows team admin user without "Add Team Members" permission to disable invite URL | CVSS3: 2.7 | 0% Низкий | больше 1 года назад | |
GHSA-3j95-8976-jfmp Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally signed firmware updates and is susceptible to processing and installing modified/malicious images. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j95-64vv-272j OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp. | CVSS3: 7.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3j94-c55m-42mx Cross-site scripting (XSS) vulnerability in openreport.jsp in IBM Maximo Asset Management 7.x before 7.1.1.12 IFIX.20140321-1336 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.12 IFIX.20140218-1510 allows remote authenticated users to inject arbitrary web script or HTML via a crafted report parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j94-8x5f-gpm9 Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360. | 1% Низкий | почти 4 года назад | ||
GHSA-3j93-7rf7-p7m6 thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter | CVSS3: 8.9 | 0% Низкий | почти 3 года назад | |
GHSA-3j93-3979-xwwx Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0939, allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Cc, and (4) Bcc parameters. | 0% Низкий | почти 4 года назад | ||
GHSA-3j8x-8x9q-3m4r In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules. | 0% Низкий | больше 1 года назад | ||
GHSA-3j8r-jf9w-5cmh LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit | CVSS3: 6.2 | 0% Низкий | 7 месяцев назад | |
GHSA-3j8r-26jq-jj7w A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-3j8q-j2j7-x49c The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-3j8q-2cfg-hm94 Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3j8p-v97g-rq93 An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version of NMC G2 which is available on the Eaton download center. | CVSS3: 4.7 | 0% Низкий | 5 месяцев назад | |
GHSA-3j8p-q74h-4pxp There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3j8m-jchc-w7pr The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j8m-4wcj-vrx5 A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=read_msg of the component POST Parameter Handler. The manipulation of the argument convo_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230348. | CVSS3: 6.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3j8g-45hc-8h5f Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3. | CVSS3: 7.6 | 0% Низкий | почти 2 года назад | |
GHSA-3j8f-xvm3-ffx4 Authorization Bypass in parse-path | CVSS3: 7.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3j89-v6qj-mgf2 LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу