Количество 314 458
Количество 314 458
GHSA-2jv5-xv66-fhx8
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.
GHSA-2jv5-wvvg-c9hj
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
GHSA-2jv5-mm7g-6r3r
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.
GHSA-2jv5-h643-m9jp
IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
GHSA-2jv5-9r88-3w3p
python-multipart vulnerable to Content-Type Header ReDoS
GHSA-2jv5-59rp-vmgj
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2jv4-vc4g-7mp7
Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
GHSA-2jv4-g2j5-gcgx
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
GHSA-2jv4-86qg-m23h
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
GHSA-2jv4-596w-g9hj
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-2jv4-4qp4-gcjc
Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.
GHSA-2jv3-v37p-65w3
CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources
GHSA-2jv3-mh5v-j4w2
Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.
GHSA-2jv3-8jp8-xgcm
Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.
GHSA-2jv2-97wr-gpc9
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
GHSA-2jrx-vp4g-6wgj
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later
GHSA-2jrx-hm6v-q9c6
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.
GHSA-2jrx-fmqr-7h3v
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.
GHSA-2jrw-7rm5-qgh5
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0."
GHSA-2jrw-3wxv-fr6m
Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2jv5-xv66-fhx8 A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function. | CVSS3: 4.6 | 0% Низкий | почти 2 года назад | |
GHSA-2jv5-wvvg-c9hj Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | 1% Низкий | больше 3 лет назад | ||
GHSA-2jv5-mm7g-6r3r SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2jv5-h643-m9jp IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token. | 0% Низкий | больше 3 лет назад | ||
GHSA-2jv5-9r88-3w3p python-multipart vulnerable to Content-Type Header ReDoS | CVSS3: 7.5 | 2% Низкий | почти 2 года назад | |
GHSA-2jv5-59rp-vmgj The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
GHSA-2jv4-vc4g-7mp7 Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service. | 0% Низкий | больше 3 лет назад | ||
GHSA-2jv4-g2j5-gcgx in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. | CVSS3: 6.1 | 0% Низкий | 8 месяцев назад | |
GHSA-2jv4-86qg-m23h The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | CVSS3: 2.7 | 0% Низкий | около 1 года назад | |
GHSA-2jv4-596w-g9hj In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
GHSA-2jv4-4qp4-gcjc Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors. | 10% Низкий | больше 3 лет назад | ||
GHSA-2jv3-v37p-65w3 CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources | CVSS3: 7.2 | 15% Средний | больше 3 лет назад | |
GHSA-2jv3-mh5v-j4w2 Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop. | 0% Низкий | почти 4 года назад | ||
GHSA-2jv3-8jp8-xgcm Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0. | CVSS3: 7.1 | 0% Низкий | 11 месяцев назад | |
GHSA-2jv2-97wr-gpc9 AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes. | 1% Низкий | больше 3 лет назад | ||
GHSA-2jrx-vp4g-6wgj A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-2jrx-hm6v-q9c6 SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected. | 1% Низкий | почти 4 года назад | ||
GHSA-2jrx-fmqr-7h3v Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-2jrw-7rm5-qgh5 IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0." | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2jrw-3wxv-fr6m Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу