Количество 301 538
Количество 301 538
GHSA-27v7-qhfv-rqq8
Insecure Credential Storage in web3
GHSA-27v6-gp7m-8rxj
Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.
GHSA-27v6-gmmm-5qf3
Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.
GHSA-27v6-4m9p-3qq4
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
GHSA-27v5-v9w4-6pr5
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
GHSA-27v5-q384-ff55
find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.
GHSA-27v5-mp7r-pc7w
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
GHSA-27v4-w7r4-68vg
Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.
GHSA-27v4-m256-2g57
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
GHSA-27v4-jvv2-r77h
SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.
GHSA-27v4-h6gj-f3w5
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).
GHSA-27v4-cjp2-mwc4
Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.
GHSA-27v4-8jv4-3cp6
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown
GHSA-27v4-4p5h-63xx
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
GHSA-27v3-wp78-r8ww
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application
GHSA-27v3-j68w-q6ph
SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-27v2-398x-f74x
MAGMI cross-site scripting (XSS)
GHSA-27rx-wrqr-qj3v
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
GHSA-27rx-w643-mrjg
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data
GHSA-27rv-vgm8-cv35
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27v7-qhfv-rqq8 Insecure Credential Storage in web3 | CVSS3: 3.3 | больше 6 лет назад | ||
GHSA-27v6-gp7m-8rxj Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory. | CVSS3: 4 | 0% Низкий | около 1 месяца назад | |
GHSA-27v6-gmmm-5qf3 Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors. | 4% Низкий | больше 3 лет назад | ||
GHSA-27v6-4m9p-3qq4 Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | CVSS3: 7.2 | 6% Низкий | около 3 лет назад | |
GHSA-27v5-v9w4-6pr5 Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF." | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-27v5-q384-ff55 find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo. | 1% Низкий | больше 3 лет назад | ||
GHSA-27v5-mp7r-pc7w Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-27v4-w7r4-68vg Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server. | CVSS3: 3.7 | 0% Низкий | больше 1 года назад | |
GHSA-27v4-m256-2g57 File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. | CVSS3: 9.8 | 9% Низкий | около 2 лет назад | |
GHSA-27v4-jvv2-r77h SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field. | 1% Низкий | больше 3 лет назад | ||
GHSA-27v4-h6gj-f3w5 A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h). | CVSS3: 4.4 | 0% Низкий | больше 3 лет назад | |
GHSA-27v4-cjp2-mwc4 Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063. | 0% Низкий | больше 3 лет назад | ||
GHSA-27v4-8jv4-3cp6 Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown | 0% Низкий | больше 3 лет назад | ||
GHSA-27v4-4p5h-63xx Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. | 0% Низкий | больше 3 лет назад | ||
GHSA-27v3-wp78-r8ww When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-27v3-j68w-q6ph SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-27v2-398x-f74x MAGMI cross-site scripting (XSS) | 5% Низкий | больше 3 лет назад | ||
GHSA-27rx-wrqr-qj3v WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1. | 1% Низкий | больше 3 лет назад | ||
GHSA-27rx-w643-mrjg In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-27rv-vgm8-cv35 A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later | CVSS3: 5.5 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу