Количество 314 458
Количество 314 458
GHSA-2ww8-f9rj-2xg5
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).
GHSA-2ww7-vv5p-929j
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
GHSA-2ww6-gh4g-5q93
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.
GHSA-2ww6-g8rg-vh7g
Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.
GHSA-2ww6-2gwx-v942
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_...
GHSA-2ww5-g3p9-xg2r
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.
GHSA-2ww5-c4rg-76jh
A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.
GHSA-2ww3-fxvq-293j
NLTK Vulnerable to REDoS
GHSA-2ww3-72rp-wpp4
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
GHSA-2ww2-4h6w-cc6c
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users
GHSA-2wvx-75wc-hc4w
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.
GHSA-2wvw-h8hc-x343
Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.
GHSA-2wvw-246g-ffw7
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.
GHSA-2wvv-vggf-ggr9
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.
GHSA-2wvv-pxv7-cgf7
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.
GHSA-2wvv-phhw-qvmc
Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting
GHSA-2wvv-6r6q-wwcj
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.
GHSA-2wvv-4p4q-7mq5
Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.
GHSA-2wvq-xm2v-3mr6
Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service (daemon crash) via vectors involving an empty treasure list.
GHSA-2wvq-34x3-5vhj
Users who were required to change their password could still access system information before changing their password
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2ww8-f9rj-2xg5 Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-2ww7-vv5p-929j PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled. | CVSS3: 7.8 | 17% Средний | больше 3 лет назад | |
GHSA-2ww6-gh4g-5q93 This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2ww6-g8rg-vh7g Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename. | 1% Низкий | почти 4 года назад | ||
GHSA-2ww6-2gwx-v942 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_... | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-2ww5-g3p9-xg2r Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php. | 11% Средний | почти 4 года назад | ||
GHSA-2ww5-c4rg-76jh A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user. | CVSS3: 5 | 0% Низкий | 10 месяцев назад | |
GHSA-2ww3-fxvq-293j NLTK Vulnerable to REDoS | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
GHSA-2ww3-72rp-wpp4 Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK | CVSS3: 9.9 | 0% Низкий | 2 дня назад | |
GHSA-2ww2-4h6w-cc6c The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2wvx-75wc-hc4w The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2wvw-h8hc-x343 Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access. | CVSS3: 3.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2wvw-246g-ffw7 Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL. | 1% Низкий | больше 3 лет назад | ||
GHSA-2wvv-vggf-ggr9 A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user. | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад | |
GHSA-2wvv-pxv7-cgf7 A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336. | CVSS3: 7.2 | 0% Низкий | около 3 лет назад | |
GHSA-2wvv-phhw-qvmc Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
GHSA-2wvv-6r6q-wwcj Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2wvv-4p4q-7mq5 Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-2wvq-xm2v-3mr6 Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service (daemon crash) via vectors involving an empty treasure list. | 0% Низкий | почти 4 года назад | ||
GHSA-2wvq-34x3-5vhj Users who were required to change their password could still access system information before changing their password | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад |
Уязвимостей на страницу