Количество 314 458
Количество 314 458
GHSA-3g63-p2hp-v8xg
eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.
GHSA-3g63-2rpp-wc2m
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
GHSA-3g62-vr55-m6hc
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
GHSA-3g62-9qpr-j338
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
GHSA-3g62-98rr-25fp
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
GHSA-3g5x-2qp3-gm68
The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-3g5w-ccf9-qgvg
In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A
GHSA-3g5w-6pw7-6hrp
Path Traversal In Eclipse GlassFish
GHSA-3g5v-m9jm-mw8w
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.
GHSA-3g5v-28p4-h3v9
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().
GHSA-3g5r-c4ph-rc9c
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
GHSA-3g5r-3c4p-wrgj
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
GHSA-3g5p-5p6j-r9qp
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3g5m-g7r7-6pwf
get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.
GHSA-3g5m-332q-27r3
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
GHSA-3g5j-8vj8-rhj3
Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.
GHSA-3g5h-5mpr-m5qx
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
GHSA-3g5g-jqgq-pgf2
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
GHSA-3g5f-wchp-h22r
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163.
GHSA-3g5f-h429-8r64
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3g63-p2hp-v8xg eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-3g63-2rpp-wc2m A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-3g62-vr55-m6hc In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-3g62-9qpr-j338 In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. | 0% Низкий | больше 3 лет назад | ||
GHSA-3g62-98rr-25fp AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system. | CVSS3: 9.8 | 34% Средний | больше 3 лет назад | |
GHSA-3g5x-2qp3-gm68 The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 9.8 | 30% Средний | больше 1 года назад | |
GHSA-3g5w-ccf9-qgvg In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-3g5w-6pw7-6hrp Path Traversal In Eclipse GlassFish | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-3g5v-m9jm-mw8w The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5v-28p4-h3v9 In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user(). | CVSS3: 7.1 | 0% Низкий | 8 месяцев назад | |
GHSA-3g5r-c4ph-rc9c A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field. | CVSS3: 4.8 | 0% Низкий | 12 месяцев назад | |
GHSA-3g5r-3c4p-wrgj A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5p-5p6j-r9qp In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.4 | 0% Низкий | почти 2 года назад | |
GHSA-3g5m-g7r7-6pwf get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3g5m-332q-27r3 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3g5j-8vj8-rhj3 Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3g5h-5mpr-m5qx SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3g5g-jqgq-pgf2 Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-3g5f-wchp-h22r Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163. | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
GHSA-3g5f-h429-8r64 The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL. | CVSS3: 9.9 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу