Количество 301 801
Количество 301 801
GHSA-28wr-vmq3-227j
A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-28wr-h897-6hmv
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
GHSA-28wq-pxv7-mr7m
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
GHSA-28wq-p9hh-3w4h
Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.
GHSA-28wp-2xch-xmx5
The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.
GHSA-28wh-2mp5-4gp8
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
GHSA-28wg-r79p-3484
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.
GHSA-28wg-8gv4-mpjf
Broken access control in Silverpeas
GHSA-28wg-555g-fr2v
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
GHSA-28wf-q2m6-rjgv
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
GHSA-28wf-jx5m-6fhg
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
GHSA-28wf-973p-g3gx
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
GHSA-28wc-7mwv-p5h3
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
GHSA-28w9-vf5c-mw9p
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.
GHSA-28w9-qhgf-j4rh
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
GHSA-28w9-f394-mqfw
Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.
GHSA-28w9-2v4x-592r
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.
GHSA-28w7-pjc6-7h5m
SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.
GHSA-28w7-9227-5wcm
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
GHSA-28w7-5v3f-jc8j
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28wr-vmq3-227j A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.5 | 0% Низкий | 3 месяца назад | |
GHSA-28wr-h897-6hmv Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-28wq-pxv7-mr7m In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | CVSS3: 7.5 | 10% Низкий | больше 3 лет назад | |
GHSA-28wq-p9hh-3w4h Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-28wp-2xch-xmx5 The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416. | 0% Низкий | больше 3 лет назад | ||
GHSA-28wh-2mp5-4gp8 Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | CVSS3: 6.1 | 0% Низкий | около 1 года назад | |
GHSA-28wg-r79p-3484 Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-28wg-8gv4-mpjf Broken access control in Silverpeas | CVSS3: 4.9 | 0% Низкий | почти 2 года назад | |
GHSA-28wg-555g-fr2v If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-28wf-q2m6-rjgv Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability. | CVSS3: 8.2 | 0% Низкий | 5 месяцев назад | |
GHSA-28wf-jx5m-6fhg An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
GHSA-28wf-973p-g3gx In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. | 0% Низкий | больше 3 лет назад | ||
GHSA-28wc-7mwv-p5h3 In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-28w9-vf5c-mw9p E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks. | 0% Низкий | больше 3 лет назад | ||
GHSA-28w9-qhgf-j4rh Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
GHSA-28w9-f394-mqfw Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets. | 8% Низкий | больше 3 лет назад | ||
GHSA-28w9-2v4x-592r Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
GHSA-28w7-pjc6-7h5m SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality. | 0% Низкий | больше 3 лет назад | ||
GHSA-28w7-9227-5wcm GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow. | CVSS3: 2.7 | 0% Низкий | 20 дней назад | |
GHSA-28w7-5v3f-jc8j An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу