Количество 300 077
Количество 300 077
GHSA-22q7-cg4r-p9mx
TYPO3 Cross-Site Scripting in Fluid ViewHelpers
GHSA-22q6-wwq7-2jj9
OpenStack Keystone Improper Authentication vulnerability
GHSA-22q6-rw64-5gjj
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
GHSA-22q6-hvj2-jgmw
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
GHSA-22q6-9rvj-cmpf
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".
GHSA-22q6-7m3g-6r77
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
GHSA-22q5-qg84-2p5f
Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.
GHSA-22q5-9phm-744v
XWiki allows unregistered users to access private pages information through REST endpoint
GHSA-22q5-57p4-rxcv
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
GHSA-22q4-f5r6-3xqw
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
GHSA-22q4-5758-44qv
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
GHSA-22q3-mmfp-g262
Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
GHSA-22q3-4v32-4m7c
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
GHSA-22q2-gf4f-hvw6
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.
GHSA-22px-9px7-pc64
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
GHSA-22pw-2xmq-86xg
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.
GHSA-22pv-7v9j-hqxp
Symfony Host Header Injection vulnerability in the HttpFoundation component
GHSA-22pv-795j-9r7p
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
GHSA-22pr-vjq7-4qcg
The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-22pr-mvmh-vgg5
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22q7-cg4r-p9mx TYPO3 Cross-Site Scripting in Fluid ViewHelpers | CVSS3: 6.1 | больше 1 года назад | ||
GHSA-22q6-wwq7-2jj9 OpenStack Keystone Improper Authentication vulnerability | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-22q6-rw64-5gjj Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
GHSA-22q6-hvj2-jgmw IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. | CVSS3: 7.1 | 0% Низкий | больше 3 лет назад | |
GHSA-22q6-9rvj-cmpf Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll". | 0% Низкий | больше 3 лет назад | ||
GHSA-22q6-7m3g-6r77 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | CVSS3: 9.1 | 16% Средний | около 1 года назад | |
GHSA-22q5-qg84-2p5f Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-22q5-9phm-744v XWiki allows unregistered users to access private pages information through REST endpoint | 0% Низкий | 8 месяцев назад | ||
GHSA-22q5-57p4-rxcv Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-22q4-f5r6-3xqw The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable. | CVSS3: 7.3 | 92% Критический | больше 1 года назад | |
GHSA-22q4-5758-44qv Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML. | 0% Низкий | больше 3 лет назад | ||
GHSA-22q3-mmfp-g262 Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image. | 2% Низкий | больше 3 лет назад | ||
GHSA-22q3-4v32-4m7c Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage. | CVSS3: 4.9 | 0% Низкий | больше 1 года назад | |
GHSA-22q2-gf4f-hvw6 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session. | 0% Низкий | около 2 месяцев назад | ||
GHSA-22px-9px7-pc64 The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. | 0% Низкий | больше 3 лет назад | ||
GHSA-22pw-2xmq-86xg Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162. | 0% Низкий | больше 3 лет назад | ||
GHSA-22pv-7v9j-hqxp Symfony Host Header Injection vulnerability in the HttpFoundation component | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-22pv-795j-9r7p Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-22pr-vjq7-4qcg The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-22pr-mvmh-vgg5 An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583. | CVSS3: 5.5 | 23% Средний | больше 3 лет назад |
Уязвимостей на страницу