Количество 312 573
Количество 312 573
GHSA-2gc7-w4hw-rr2m
class.upload.php in verot.net omits .pht from the set of dangerous file extensions
GHSA-2gc7-9j5g-v42f
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
GHSA-2gc7-6pfc-v239
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
GHSA-2gc6-xpq3-f7gm
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
GHSA-2gc6-9pfx-xpg3
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.
GHSA-2gc6-52qh-cwwj
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
GHSA-2gc6-2h2g-ph48
Rambox RCE Vulnerability
GHSA-2gc5-r3m4-5vgx
An issue in the permission and access control components within ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to gain escalate privileges.
GHSA-2gc5-pcr2-vmgm
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2gc5-3h3p-8vpf
Dolibarr reflected cross-site scripting (XSS) vulnerability
GHSA-2gc3-gxvv-r87c
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
GHSA-2gc3-8h7p-8j99
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
GHSA-2gc2-cm86-3pjx
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
GHSA-2gc2-4gm5-9ghf
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.
GHSA-2g9x-g93g-hv56
In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.
GHSA-2g9w-mw43-7j8w
A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258202 is the identifier assigned to this vulnerability.
GHSA-2g9r-w7mh-f2h2
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2g9r-9mj3-xx54
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
GHSA-2g9r-9f99-v27g
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.
GHSA-2g9r-93qh-95qh
HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2gc7-w4hw-rr2m class.upload.php in verot.net omits .pht from the set of dangerous file extensions | CVSS3: 9.8 | 15% Средний | почти 6 лет назад | |
GHSA-2gc7-9j5g-v42f GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | CVSS3: 9.8 | 28% Средний | почти 3 года назад | |
GHSA-2gc7-6pfc-v239 Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-2gc6-xpq3-f7gm A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | CVSS3: 6.7 | 0% Низкий | почти 4 года назад | |
GHSA-2gc6-9pfx-xpg3 Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068. | 24% Средний | больше 3 лет назад | ||
GHSA-2gc6-52qh-cwwj Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129. | 52% Средний | почти 4 года назад | ||
GHSA-2gc6-2h2g-ph48 Rambox RCE Vulnerability | CVSS3: 9 | 5% Низкий | больше 3 лет назад | |
GHSA-2gc5-r3m4-5vgx An issue in the permission and access control components within ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to gain escalate privileges. | CVSS3: 9.8 | около 2 лет назад | ||
GHSA-2gc5-pcr2-vmgm The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-2gc5-3h3p-8vpf Dolibarr reflected cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2gc3-gxvv-r87c Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-2gc3-8h7p-8j99 An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2gc2-cm86-3pjx In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2gc2-4gm5-9ghf The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2g9x-g93g-hv56 In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-2g9w-mw43-7j8w A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258202 is the identifier assigned to this vulnerability. | CVSS3: 7.3 | 0% Низкий | почти 2 года назад | |
GHSA-2g9r-w7mh-f2h2 A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.8 | 0% Низкий | 8 месяцев назад | |
GHSA-2g9r-9mj3-xx54 Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. | CVSS3: 4.4 | 0% Низкий | почти 4 года назад | |
GHSA-2g9r-9f99-v27g yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2g9r-93qh-95qh HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу