Количество 314 212
Количество 314 212
GHSA-2j4v-jvmw-mq8v
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
GHSA-2j4r-v4xj-p2f4
Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.
GHSA-2j4r-j436-59p3
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
GHSA-2j4q-9fff-236j
Apache Struts XSS Vulnerability
GHSA-2j4p-5xx5-582x
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.
GHSA-2j4p-2hc9-62f4
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
GHSA-2j4j-cgfm-hpg2
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
GHSA-2j4h-qfp4-82q7
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
GHSA-2j4h-p58q-g7mp
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
GHSA-2j4h-mgwq-9x58
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.
GHSA-2j4h-cjgh-659v
Reflected XSS vulnerability in Jenkins VncViewer Plugin
GHSA-2j4h-89r3-h3f3
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
GHSA-2j4h-4639-xjfj
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
GHSA-2j4g-v4fv-rhwg
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
GHSA-2j4g-q4pc-fmcw
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
GHSA-2j4g-7q2x-6pmv
Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
GHSA-2j4f-52m8-xq9h
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.
GHSA-2j4c-pqxj-mfqh
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
GHSA-2j4c-9qqq-896r
web3-core-method is vulnerable to prototype pollution
GHSA-2j4c-6m6h-f5hg
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2j4v-jvmw-mq8v IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j4r-v4xj-p2f4 Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-2j4r-j436-59p3 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. | CVSS3: 7.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2j4q-9fff-236j Apache Struts XSS Vulnerability | CVSS3: 6.1 | 7% Низкий | больше 3 лет назад | |
GHSA-2j4p-5xx5-582x IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j4p-2hc9-62f4 Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-2j4j-cgfm-hpg2 SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-2j4h-qfp4-82q7 Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | 80% Высокий | почти 4 года назад | ||
GHSA-2j4h-p58q-g7mp Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j4h-mgwq-9x58 The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization. | 8% Низкий | больше 3 лет назад | ||
GHSA-2j4h-cjgh-659v Reflected XSS vulnerability in Jenkins VncViewer Plugin | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2j4h-89r3-h3f3 The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | 1% Низкий | почти 4 года назад | ||
GHSA-2j4h-4639-xjfj Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9. | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
GHSA-2j4g-v4fv-rhwg Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability | CVSS3: 7.2 | 87% Высокий | почти 2 года назад | |
GHSA-2j4g-q4pc-fmcw Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2j4g-7q2x-6pmv Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2j4f-52m8-xq9h The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely. | CVSS3: 8.8 | 1% Низкий | почти 3 года назад | |
GHSA-2j4c-pqxj-mfqh Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-2j4c-9qqq-896r web3-core-method is vulnerable to prototype pollution | 0% Низкий | 5 месяцев назад | ||
GHSA-2j4c-6m6h-f5hg suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу