Количество 301 694
Количество 301 694
GHSA-2884-65gj-953q
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
GHSA-2884-62f5-6m65
In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
GHSA-2883-9xj8-6c3x
An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
GHSA-2883-8qjj-chw7
The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-2882-xfpf-chqj
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aelora iframe Wrapper allows DOM-Based XSS. This issue affects iframe Wrapper: from n/a through 0.1.1.
GHSA-287x-hf3r-74ch
Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.
GHSA-287x-c836-c4c9
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.
GHSA-287x-9rff-qvcg
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
GHSA-287x-6r2h-f9mw
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
GHSA-287x-67g2-7wf2
Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors.
GHSA-287x-2333-6cmc
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
GHSA-287w-9xcw-2gqp
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some unknown functionality of the file /useratte/resmanage.php. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264530 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
GHSA-287v-43mw-3ff7
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
GHSA-287r-v59r-8g28
The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.
GHSA-287r-574x-f4h4
RosarioSIS XSS Vulnerability
GHSA-287r-36rw-cfgc
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
GHSA-287q-rcxw-c7c5
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and Information disclosure.
GHSA-287q-jfcp-9vhv
django-photologue vulnerable to Cross-site Scripting
GHSA-287m-mj3j-wvc9
A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.
GHSA-287m-m4rw-v572
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2884-65gj-953q Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=. | CVSS3: 7.2 | 0% Низкий | больше 2 лет назад | |
GHSA-2884-62f5-6m65 In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5) | CVSS3: 8 | 0% Низкий | 11 месяцев назад | |
GHSA-2883-9xj8-6c3x An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2883-8qjj-chw7 The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-2882-xfpf-chqj Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aelora iframe Wrapper allows DOM-Based XSS. This issue affects iframe Wrapper: from n/a through 0.1.1. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-287x-hf3r-74ch Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-287x-c836-c4c9 The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file. | 2% Низкий | больше 3 лет назад | ||
GHSA-287x-9rff-qvcg Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
GHSA-287x-6r2h-f9mw UnoPim vulnerable to CSRF on Product edit feature and creation of other types | 0% Низкий | 3 месяца назад | ||
GHSA-287x-67g2-7wf2 Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-287x-2333-6cmc Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet. | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
GHSA-287w-9xcw-2gqp ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some unknown functionality of the file /useratte/resmanage.php. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264530 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. | CVSS3: 6.3 | 2% Низкий | больше 1 года назад | |
GHSA-287v-43mw-3ff7 An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-287r-v59r-8g28 The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-287r-574x-f4h4 RosarioSIS XSS Vulnerability | 23% Средний | почти 4 года назад | ||
GHSA-287r-36rw-cfgc The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | 22% Средний | больше 3 лет назад | ||
GHSA-287q-rcxw-c7c5 Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and Information disclosure. | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
GHSA-287q-jfcp-9vhv django-photologue vulnerable to Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | почти 3 года назад | |
GHSA-287m-mj3j-wvc9 A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files. | 0% Низкий | больше 3 лет назад | ||
GHSA-287m-m4rw-v572 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function. | CVSS3: 8 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу