Количество 301 024
Количество 301 024
GHSA-26j2-cp35-2r7f
IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.
GHSA-26j2-2wp8-h95h
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort.
GHSA-26hx-v824-3wvf
** DISPUTED ** Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account."
GHSA-26hx-622f-3855
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
GHSA-26hw-262c-g9gc
Exposure of sensitive information vulnerability in Jenkins Black Duck Hub Plugin
GHSA-26hv-67m6-qjff
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
GHSA-26hr-q7pj-w334
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
GHSA-26hr-q2wp-rvc5
User with permission to write actions can impersonate another user when auth token is configured in environment variable
GHSA-26hr-9q73-x3wm
SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.
GHSA-26hr-4x6c-5c7x
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
GHSA-26hq-r45f-3pr8
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K.
GHSA-26hq-7m9g-65cf
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
GHSA-26hq-7286-mg8f
Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability
GHSA-26hp-vwv6-p4qg
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.
GHSA-26hp-m9gv-2j62
Deserialization of Untrusted Data vulnerability in Gabriele Valenti Telecash Ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through 2.2.
GHSA-26hp-cgjj-m2j3
fuel/core ImageMagick driver does not escape all shell arguments.
GHSA-26hm-r6mg-963c
SQL Injection in JeecgBoot
GHSA-26hm-gghq-x5rr
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
GHSA-26hm-cr9c-2627
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
GHSA-26hm-c7gj-q5mp
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-26j2-cp35-2r7f IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-26j2-2wp8-h95h In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort. | CVSS3: 9.8 | 0% Низкий | почти 3 года назад | |
GHSA-26hx-v824-3wvf ** DISPUTED ** Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account." | 0% Низкий | больше 3 лет назад | ||
GHSA-26hx-622f-3855 Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete. | CVSS3: 9.1 | 1 день назад | ||
GHSA-26hw-262c-g9gc Exposure of sensitive information vulnerability in Jenkins Black Duck Hub Plugin | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-26hv-67m6-qjff Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-26hr-q7pj-w334 Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-26hr-q2wp-rvc5 User with permission to write actions can impersonate another user when auth token is configured in environment variable | CVSS3: 6.2 | почти 2 года назад | ||
GHSA-26hr-9q73-x3wm SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php. | 1% Низкий | больше 3 лет назад | ||
GHSA-26hr-4x6c-5c7x The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | CVSS3: 4.8 | 0% Низкий | больше 1 года назад | |
GHSA-26hq-r45f-3pr8 On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-26hq-7m9g-65cf Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-26hq-7286-mg8f Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability | больше 1 года назад | |||
GHSA-26hp-vwv6-p4qg The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-26hp-m9gv-2j62 Deserialization of Untrusted Data vulnerability in Gabriele Valenti Telecash Ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through 2.2. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-26hp-cgjj-m2j3 fuel/core ImageMagick driver does not escape all shell arguments. | больше 1 года назад | |||
GHSA-26hm-r6mg-963c SQL Injection in JeecgBoot | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-26hm-gghq-x5rr An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c. | CVSS3: 7.5 | 21% Средний | больше 3 лет назад | |
GHSA-26hm-cr9c-2627 The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-26hm-c7gj-q5mp Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу