Количество 314 458
Количество 314 458
GHSA-2xwv-25cq-66xr
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
GHSA-2xwr-53m3-98jw
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.
GHSA-2xwq-p62f-cjrm
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.
GHSA-2xwq-h7r9-6w27
Cross-site Scripting in kimai2
GHSA-2xwq-3g46-4j22
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover
GHSA-2xwp-m7mq-7q3r
CLI does not correctly implement strict mode
GHSA-2xwp-jx33-g2fj
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
GHSA-2xwp-gm9f-mwxv
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.
GHSA-2xwp-7j3p-c78x
Cross site scripting in SiteServer CMS
GHSA-2xwp-3v4p-x875
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
GHSA-2xwm-mmjj-m5x4
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.
GHSA-2xwm-j535-wh92
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
GHSA-2xwm-fqp4-pw7f
Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.
GHSA-2xwm-f2v4-92vh
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
GHSA-2xwj-vx39-jqg9
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33.
GHSA-2xwj-vc46-67hj
Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7.
GHSA-2xwj-rw2w-xr5q
All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.
GHSA-2xwj-g27r-p9cr
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program.
GHSA-2xwj-cxrx-46h4
Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.
GHSA-2xwj-6795-v7p4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2xwv-25cq-66xr An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords. | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-2xwr-53m3-98jw SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-2xwq-p62f-cjrm PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwq-h7r9-6w27 Cross-site Scripting in kimai2 | CVSS3: 4.6 | 0% Низкий | около 4 лет назад | |
GHSA-2xwq-3g46-4j22 Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-2xwp-m7mq-7q3r CLI does not correctly implement strict mode | больше 5 лет назад | |||
GHSA-2xwp-jx33-g2fj NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwp-gm9f-mwxv Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-2xwp-7j3p-c78x Cross site scripting in SiteServer CMS | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwp-3v4p-x875 Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-2xwm-mmjj-m5x4 SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO. | 1% Низкий | больше 3 лет назад | ||
GHSA-2xwm-j535-wh92 The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-2xwm-fqp4-pw7f Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands. | 0% Низкий | почти 4 года назад | ||
GHSA-2xwm-f2v4-92vh Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-2xwj-vx39-jqg9 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2xwj-vc46-67hj Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-2xwj-rw2w-xr5q All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwj-g27r-p9cr An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwj-cxrx-46h4 Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540. | 1% Низкий | больше 3 лет назад | ||
GHSA-2xwj-6795-v7p4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5. | CVSS3: 7.1 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу