Количество 312 573
Количество 312 573
GHSA-2m7w-32cj-4pj7
The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.
GHSA-2m7v-wmjf-9gq6
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
GHSA-2m7v-fvqp-gr2c
A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-2m7v-8fgj-5354
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.
GHSA-2m7r-x6hh-8373
A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257377 was assigned to this vulnerability.
GHSA-2m7r-mqpg-x97r
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
GHSA-2m7r-8x5f-v32g
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
GHSA-2m7r-8cjp-ww5h
The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
GHSA-2m7q-gxv6-mxf5
Remote code execution in Hanwha Techwin Smartcams
GHSA-2m7p-qcqr-gfv2
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
GHSA-2m7m-jhx5-8crh
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
GHSA-2m7m-j3mq-9g6p
A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.
GHSA-2m7m-3qp3-4h9x
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
GHSA-2m7j-prfm-384p
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
GHSA-2m7j-4ff8-h52q
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
GHSA-2m7h-86qq-fp4v
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params
GHSA-2m7h-5m38-vhh4
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-2m7g-9q74-9m3q
Improper Certificate Validation in Apache Beam
GHSA-2m7g-9m2h-fmjg
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
GHSA-2m7g-78xc-qr55
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2m7w-32cj-4pj7 The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack. | CVSS3: 3.8 | 0% Низкий | 4 месяца назад | |
GHSA-2m7v-wmjf-9gq6 Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-2m7v-fvqp-gr2c A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.7 | 0% Низкий | около 1 года назад | |
GHSA-2m7v-8fgj-5354 Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-2m7r-x6hh-8373 A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257377 was assigned to this vulnerability. | CVSS3: 6.3 | 0% Низкий | почти 2 года назад | |
GHSA-2m7r-mqpg-x97r A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2m7r-8x5f-v32g list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-2m7r-8cjp-ww5h The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2m7q-gxv6-mxf5 Remote code execution in Hanwha Techwin Smartcams | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
GHSA-2m7p-qcqr-gfv2 The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. | CVSS3: 6.7 | 65% Средний | больше 3 лет назад | |
GHSA-2m7m-jhx5-8crh IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-2m7m-j3mq-9g6p A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used. | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад | |
GHSA-2m7m-3qp3-4h9x IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741. | 0% Низкий | больше 3 лет назад | ||
GHSA-2m7j-prfm-384p Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code. | 9% Низкий | почти 4 года назад | ||
GHSA-2m7j-4ff8-h52q Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2m7h-86qq-fp4v Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params | CVSS3: 8.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2m7h-5m38-vhh4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
GHSA-2m7g-9q74-9m3q Improper Certificate Validation in Apache Beam | CVSS3: 7.5 | 0% Низкий | почти 6 лет назад | |
GHSA-2m7g-9m2h-fmjg Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-2m7g-78xc-qr55 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу