Количество 301 694
Количество 301 694
GHSA-28m2-fhxm-fxx6
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS
GHSA-28m2-22hr-gx8q
Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2.
GHSA-28jx-5cwg-xq36
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
GHSA-28jw-6mhj-hjwx
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).
GHSA-28jw-278j-42f5
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.
GHSA-28jr-36gh-qwvh
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
GHSA-28jq-qqpg-7xm4
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
GHSA-28jq-f9q3-32fc
SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-28jp-g4gg-47fp
On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements.
GHSA-28jp-5r9q-jh8r
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
GHSA-28jp-44vh-q42h
Keras keras.utils.get_file API is vulnerable to a path traversal attack
GHSA-28jm-jxrw-gvxg
The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into the command shell of the TropOS 4th Gen device. The injected commands can be exploited to execute several set-uid (SUID) applications to ultimately gain root access to the TropOS device.
GHSA-28jm-hff2-853w
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.
GHSA-28jm-h53g-x4fr
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
GHSA-28jm-43f2-h9jm
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers.
GHSA-28jj-p35h-662j
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
GHSA-28jj-97w4-wxm3
Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.
GHSA-28jh-gp7h-pj6v
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.
GHSA-28jh-5pxq-q92w
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
GHSA-28jg-wmv9-mfgw
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28m2-fhxm-fxx6 fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-28m2-22hr-gx8q Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2. | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад | |
GHSA-28jx-5cwg-xq36 Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | CVSS3: 3.5 | 19% Средний | больше 3 лет назад | |
GHSA-28jw-6mhj-hjwx Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N). | 0% Низкий | больше 3 лет назад | ||
GHSA-28jw-278j-42f5 Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-28jr-36gh-qwvh The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php. | CVSS3: 6.1 | 16% Средний | больше 3 лет назад | |
GHSA-28jq-qqpg-7xm4 Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | CVSS3: 7.8 | 4% Низкий | больше 3 лет назад | |
GHSA-28jq-f9q3-32fc SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-28jp-g4gg-47fp On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28jp-5r9q-jh8r Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-28jp-44vh-q42h Keras keras.utils.get_file API is vulnerable to a path traversal attack | 0% Низкий | 15 дней назад | ||
GHSA-28jm-jxrw-gvxg The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into the command shell of the TropOS 4th Gen device. The injected commands can be exploited to execute several set-uid (SUID) applications to ultimately gain root access to the TropOS device. | 0% Низкий | 18 дней назад | ||
GHSA-28jm-hff2-853w Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information. | 3% Низкий | больше 3 лет назад | ||
GHSA-28jm-h53g-x4fr Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | CVSS3: 6.2 | 0% Низкий | 4 месяца назад | |
GHSA-28jm-43f2-h9jm Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-28jj-p35h-662j Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-28jj-97w4-wxm3 Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-28jh-gp7h-pj6v Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279. | 39% Средний | больше 3 лет назад | ||
GHSA-28jh-5pxq-q92w Memory corruption may occour while generating test pattern due to negative indexing of display ID. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-28jg-wmv9-mfgw In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу