Количество 301 801
Количество 301 801
GHSA-2928-r2w9-gm4x
Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
GHSA-2928-6w5x-9xm3
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
GHSA-2927-hv3p-f3vp
Open redirect in caddy
GHSA-2924-xwpv-8gcj
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.
GHSA-2924-mp4r-x286
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
GHSA-2924-9cv7-3gpq
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.
GHSA-2924-22w3-7pm7
Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.
GHSA-2923-cx8w-xvxh
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.
GHSA-28xx-8j99-m32j
Malicious Package in nginxbeautifier
GHSA-28xx-6gh9-8gp4
A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
GHSA-28xx-46x6-h92x
A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.
GHSA-28xw-m7jp-89ch
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
GHSA-28xv-h724-wvrh
The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
GHSA-28xv-77rw-c8pr
NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.
GHSA-28xr-x3rf-rhgr
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
GHSA-28xr-rgjv-2mgp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA-28xr-mwxg-3qc8
Command injection in simple-git
GHSA-28xq-f23c-p68m
Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.
GHSA-28xq-93rr-jp78
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
GHSA-28xp-g7f6-7mhf
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2928-r2w9-gm4x Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. | CVSS3: 5 | 0% Низкий | 25 дней назад | |
GHSA-2928-6w5x-9xm3 i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2927-hv3p-f3vp Open redirect in caddy | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2924-xwpv-8gcj IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2924-mp4r-x286 The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2924-9cv7-3gpq An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges. | 1% Низкий | больше 3 лет назад | ||
GHSA-2924-22w3-7pm7 Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091. | 8% Низкий | больше 3 лет назад | ||
GHSA-2923-cx8w-xvxh Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request. | 6% Низкий | больше 3 лет назад | ||
GHSA-28xx-8j99-m32j Malicious Package in nginxbeautifier | CVSS3: 9.8 | около 5 лет назад | ||
GHSA-28xx-6gh9-8gp4 A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | 21% Средний | больше 3 лет назад | ||
GHSA-28xx-46x6-h92x A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611. | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
GHSA-28xw-m7jp-89ch sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805. | CVSS3: 8.8 | 5% Низкий | больше 3 лет назад | |
GHSA-28xv-h724-wvrh The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | CVSS3: 6.1 | 0% Низкий | 10 месяцев назад | |
GHSA-28xv-77rw-c8pr NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy. | 1% Низкий | больше 3 лет назад | ||
GHSA-28xr-x3rf-rhgr A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. | 0% Низкий | больше 3 лет назад | ||
GHSA-28xr-rgjv-2mgp Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 4.9 | 49% Средний | почти 3 года назад | |
GHSA-28xr-mwxg-3qc8 Command injection in simple-git | CVSS3: 8.1 | 2% Низкий | больше 3 лет назад | |
GHSA-28xq-f23c-p68m Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-28xq-93rr-jp78 EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance. | CVSS3: 9.8 | 5% Низкий | больше 3 лет назад | |
GHSA-28xp-g7f6-7mhf Syncthing vulnerable to symlink traversal and arbitrary file overwrite | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу