Количество 314 212
Количество 314 212
GHSA-3g64-6hgp-5m64
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.
GHSA-3g64-2wg6-7p8r
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.
GHSA-3g63-p2hp-v8xg
eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.
GHSA-3g63-2rpp-wc2m
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
GHSA-3g62-vr55-m6hc
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
GHSA-3g62-9qpr-j338
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
GHSA-3g62-98rr-25fp
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
GHSA-3g5x-2qp3-gm68
The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-3g5w-ccf9-qgvg
In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A
GHSA-3g5w-6pw7-6hrp
Path Traversal In Eclipse GlassFish
GHSA-3g5v-m9jm-mw8w
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.
GHSA-3g5v-28p4-h3v9
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().
GHSA-3g5r-c4ph-rc9c
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
GHSA-3g5r-3c4p-wrgj
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
GHSA-3g5p-5p6j-r9qp
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3g5m-g7r7-6pwf
get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.
GHSA-3g5m-332q-27r3
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
GHSA-3g5j-8vj8-rhj3
Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.
GHSA-3g5h-5mpr-m5qx
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
GHSA-3g5g-jqgq-pgf2
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3g64-6hgp-5m64 Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6. | CVSS3: 10 | 0% Низкий | около 1 года назад | |
GHSA-3g64-2wg6-7p8r Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component. | CVSS3: 5.4 | 1% Низкий | почти 2 года назад | |
GHSA-3g63-p2hp-v8xg eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-3g63-2rpp-wc2m A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-3g62-vr55-m6hc In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-3g62-9qpr-j338 In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. | 0% Низкий | больше 3 лет назад | ||
GHSA-3g62-98rr-25fp AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system. | CVSS3: 9.8 | 34% Средний | больше 3 лет назад | |
GHSA-3g5x-2qp3-gm68 The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 9.8 | 30% Средний | больше 1 года назад | |
GHSA-3g5w-ccf9-qgvg In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-3g5w-6pw7-6hrp Path Traversal In Eclipse GlassFish | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-3g5v-m9jm-mw8w The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5v-28p4-h3v9 In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user(). | CVSS3: 7.1 | 0% Низкий | 8 месяцев назад | |
GHSA-3g5r-c4ph-rc9c A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field. | CVSS3: 4.8 | 0% Низкий | 12 месяцев назад | |
GHSA-3g5r-3c4p-wrgj A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5p-5p6j-r9qp In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
GHSA-3g5m-g7r7-6pwf get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3g5m-332q-27r3 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5j-8vj8-rhj3 Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3g5h-5mpr-m5qx SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3g5g-jqgq-pgf2 Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу