Количество 300 899
Количество 300 899
GHSA-25hc-2p68-qc2g
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
GHSA-25h9-28j4-4h3g
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.
GHSA-25h8-g2f4-5mwj
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.
GHSA-25h8-7qpw-h33r
Rejected reason: Not used
GHSA-25h7-w4hq-hgjg
Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.
GHSA-25h7-qcgx-8445
An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.
GHSA-25h7-f24x-98pg
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors.
GHSA-25h6-xmmh-34gc
Microsoft Digest Authentication Remote Code Execution Vulnerability
GHSA-25h5-rq96-q5mq
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).
GHSA-25h5-m4r3-86jm
Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.
GHSA-25h4-xpfg-774m
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.
GHSA-25h4-w2qr-hmpx
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355.
GHSA-25h3-mw3p-w8r7
Dolibarr CRM allows Privilege Escalation
GHSA-25h2-xj4x-29h3
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
GHSA-25gx-qr96-f826
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.
GHSA-25gw-crq8-3qhc
An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
GHSA-25gw-4pcc-45cf
Deserialization of Untrusted Data in Apache Batik
GHSA-25gv-wg6f-6frp
Centreon SQL Injection vulnerability via esc_name parameter
GHSA-25gv-mvm7-5h3h
Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin
GHSA-25gv-jrjg-43pj
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-25hc-2p68-qc2g MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1 | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-25h9-28j4-4h3g Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables. | 5% Низкий | больше 3 лет назад | ||
GHSA-25h8-g2f4-5mwj Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-25h8-7qpw-h33r Rejected reason: Not used | 3 дня назад | |||
GHSA-25h7-w4hq-hgjg Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry. | 0% Низкий | больше 3 лет назад | ||
GHSA-25h7-qcgx-8445 An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365. | 0% Низкий | больше 3 лет назад | ||
GHSA-25h7-f24x-98pg Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-25h6-xmmh-34gc Microsoft Digest Authentication Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | 9 месяцев назад | |
GHSA-25h5-rq96-q5mq In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c). | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-25h5-m4r3-86jm Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-25h4-xpfg-774m Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643. | CVSS3: 7.3 | 0% Низкий | больше 3 лет назад | |
GHSA-25h4-w2qr-hmpx This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-25h3-mw3p-w8r7 Dolibarr CRM allows Privilege Escalation | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-25h2-xj4x-29h3 Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-25gx-qr96-f826 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-25gw-crq8-3qhc An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-25gw-4pcc-45cf Deserialization of Untrusted Data in Apache Batik | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-25gv-wg6f-6frp Centreon SQL Injection vulnerability via esc_name parameter | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-25gv-mvm7-5h3h Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-25gv-jrjg-43pj A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу