Количество 314 375
Количество 314 375
GHSA-2j4p-2hc9-62f4
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
GHSA-2j4j-cgfm-hpg2
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
GHSA-2j4h-qfp4-82q7
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
GHSA-2j4h-p58q-g7mp
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
GHSA-2j4h-mgwq-9x58
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.
GHSA-2j4h-cjgh-659v
Reflected XSS vulnerability in Jenkins VncViewer Plugin
GHSA-2j4h-89r3-h3f3
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
GHSA-2j4h-4639-xjfj
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
GHSA-2j4g-v4fv-rhwg
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
GHSA-2j4g-q4pc-fmcw
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
GHSA-2j4g-7q2x-6pmv
Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
GHSA-2j4f-52m8-xq9h
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.
GHSA-2j4c-pqxj-mfqh
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
GHSA-2j4c-9qqq-896r
web3-core-method is vulnerable to prototype pollution
GHSA-2j4c-6m6h-f5hg
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
GHSA-2j4c-4vw2-9r77
A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.
GHSA-2j49-q898-whm9
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
GHSA-2j49-6mmc-22jj
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.
GHSA-2j49-4qxc-q53v
Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.
GHSA-2j49-3cqv-33p2
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2j4p-2hc9-62f4 Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-2j4j-cgfm-hpg2 SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-2j4h-qfp4-82q7 Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | 80% Высокий | почти 4 года назад | ||
GHSA-2j4h-p58q-g7mp Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j4h-mgwq-9x58 The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization. | 8% Низкий | больше 3 лет назад | ||
GHSA-2j4h-cjgh-659v Reflected XSS vulnerability in Jenkins VncViewer Plugin | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2j4h-89r3-h3f3 The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | 1% Низкий | почти 4 года назад | ||
GHSA-2j4h-4639-xjfj Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9. | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
GHSA-2j4g-v4fv-rhwg Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability | CVSS3: 7.2 | 87% Высокий | почти 2 года назад | |
GHSA-2j4g-q4pc-fmcw Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2j4g-7q2x-6pmv Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Install - Configuration). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2j4f-52m8-xq9h The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely. | CVSS3: 8.8 | 1% Низкий | почти 3 года назад | |
GHSA-2j4c-pqxj-mfqh Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-2j4c-9qqq-896r web3-core-method is vulnerable to prototype pollution | 0% Низкий | 5 месяцев назад | ||
GHSA-2j4c-6m6h-f5hg suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege. | 0% Низкий | почти 4 года назад | ||
GHSA-2j4c-4vw2-9r77 A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2j49-q898-whm9 Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | CVSS3: 9.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2j49-6mmc-22jj All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2j49-4qxc-q53v Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j49-3cqv-33p2 unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу