Количество 314 691
Количество 314 691
GHSA-38hx-3542-8fh3
Malicious code in `electorn`
GHSA-38hw-368m-7jmg
Jenkins Ansible Plugin stores and displays secrets in plain text
GHSA-38hv-wgp2-rgf9
Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.
GHSA-38hv-w5wp-prfp
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.
GHSA-38hv-gjp4-4fjh
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-197960597
GHSA-38hr-xqm9-hhg9
An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes.
GHSA-38hq-wrmm-5f58
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.
GHSA-38hp-jh3g-fr6g
A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
GHSA-38hp-c2qq-q6vh
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.
GHSA-38hp-3f6w-vm5w
Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.
GHSA-38hm-hx7f-67mv
Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
GHSA-38hm-287h-q3wv
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-38hj-x9j8-7x34
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.
GHSA-38hj-p2p8-hhm2
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
GHSA-38hj-9hq2-w2gj
A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
GHSA-38hj-4492-g88q
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
GHSA-38hh-r6wr-38f6
yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
GHSA-38hh-g82x-9mpc
Windows Media Remote Code Execution Vulnerability
GHSA-38hg-q2gf-cgvf
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
GHSA-38hg-hvc8-v572
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-38hx-3542-8fh3 Malicious code in `electorn` | больше 5 лет назад | |||
GHSA-38hw-368m-7jmg Jenkins Ansible Plugin stores and displays secrets in plain text | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-38hv-wgp2-rgf9 Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files. | 0% Низкий | больше 3 лет назад | ||
GHSA-38hv-w5wp-prfp Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-38hv-gjp4-4fjh In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-197960597 | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-38hr-xqm9-hhg9 An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-38hq-wrmm-5f58 An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory. | 0% Низкий | больше 3 лет назад | ||
GHSA-38hp-jh3g-fr6g A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
GHSA-38hp-c2qq-q6vh The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file. | 0% Низкий | больше 3 лет назад | ||
GHSA-38hp-3f6w-vm5w Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-38hm-hx7f-67mv Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-38hm-287h-q3wv The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
GHSA-38hj-x9j8-7x34 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-38hj-p2p8-hhm2 HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response. | 58% Средний | больше 3 лет назад | ||
GHSA-38hj-9hq2-w2gj A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
GHSA-38hj-4492-g88q INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-38hh-r6wr-38f6 yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp. | 7% Низкий | почти 4 года назад | ||
GHSA-38hh-g82x-9mpc Windows Media Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | больше 3 лет назад | |
GHSA-38hg-q2gf-cgvf Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-38hg-hvc8-v572 Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу