Количество 301 538
Количество 301 538
GHSA-27ww-388c-hfhf
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.
GHSA-27wv-g8h4-3qr9
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
GHSA-27wr-6xhx-m89g
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 136 and 7.x before 7.1.1 on Windows allows remote attackers to cause a denial of service (filtering outage) via a crafted sequence of characters in a URI.
GHSA-27wr-2vmx-7hq4
A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.2.8 is able to address this issue. The name of the patch is e23559b98c8ea2957f09978c29f4e512ba789eb6. It is recommended to upgrade the affected component.
GHSA-27wq-qx3q-fxm9
Improper Handling of Unexpected Data Type in ced
GHSA-27wq-9xfm-724g
An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
GHSA-27wq-44rw-m6wh
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.
GHSA-27wp-xpgf-2rjq
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.
GHSA-27wp-x9q2-grf8
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-27wp-jvhw-v4xp
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
GHSA-27wp-chg4-ffw3
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
GHSA-27wm-p6hh-jm27
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.
GHSA-27wj-6vjv-96mm
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
GHSA-27wh-h3mm-7hf3
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.
GHSA-27wg-r456-jc87
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.
GHSA-27wg-m2hx-ww9m
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.
GHSA-27wg-jv26-vh4g
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
GHSA-27wg-99g8-2v4v
Rust EVM erroneousle handles `record_external_operation` error return
GHSA-27wg-3m5v-r5fh
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.
GHSA-27wf-jhgm-qm73
The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27ww-388c-hfhf An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. | CVSS3: 7.6 | 0% Низкий | 7 месяцев назад | |
GHSA-27wv-g8h4-3qr9 IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system. | CVSS3: 3.3 | 0% Низкий | 9 месяцев назад | |
GHSA-27wr-6xhx-m89g The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 136 and 7.x before 7.1.1 on Windows allows remote attackers to cause a denial of service (filtering outage) via a crafted sequence of characters in a URI. | 0% Низкий | больше 3 лет назад | ||
GHSA-27wr-2vmx-7hq4 A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.2.8 is able to address this issue. The name of the patch is e23559b98c8ea2957f09978c29f4e512ba789eb6. It is recommended to upgrade the affected component. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
GHSA-27wq-qx3q-fxm9 Improper Handling of Unexpected Data Type in ced | CVSS3: 7.5 | 0% Низкий | около 4 лет назад | |
GHSA-27wq-9xfm-724g An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | CVSS3: 7.5 | 1% Низкий | 10 месяцев назад | |
GHSA-27wq-44rw-m6wh Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password. | 3% Низкий | больше 3 лет назад | ||
GHSA-27wp-xpgf-2rjq A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. | 0% Низкий | больше 3 лет назад | ||
GHSA-27wp-x9q2-grf8 SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-27wp-jvhw-v4xp Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag | CVSS3: 8.3 | 1% Низкий | больше 1 года назад | |
GHSA-27wp-chg4-ffw3 An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component. | CVSS3: 8.2 | 0% Низкий | 9 месяцев назад | |
GHSA-27wm-p6hh-jm27 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-27wj-6vjv-96mm Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-27wh-h3mm-7hf3 FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument. | 0% Низкий | больше 3 лет назад | ||
GHSA-27wg-r456-jc87 A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability. | CVSS3: 5.3 | 28% Средний | почти 2 года назад | |
GHSA-27wg-m2hx-ww9m Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-27wg-jv26-vh4g login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. | 5% Низкий | больше 3 лет назад | ||
GHSA-27wg-99g8-2v4v Rust EVM erroneousle handles `record_external_operation` error return | CVSS3: 5.9 | 1% Низкий | почти 2 года назад | |
GHSA-27wg-3m5v-r5fh Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-27wf-jhgm-qm73 The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | CVSS3: 4.9 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу