Количество 314 375
Количество 314 375
GHSA-2hjx-qmr7-gg4r
An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call
GHSA-2hjx-g8mm-qjgv
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization.
GHSA-2hjw-jh9v-m769
Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.
GHSA-2hjw-hf33-2w8v
Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.
GHSA-2hjw-h4fr-9x35
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
GHSA-2hjv-5gg5-2v4c
Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-2hjr-wwf2-rh3g
Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745.
GHSA-2hjr-vmf3-xwvp
Elasticsearch Insertion of Sensitive Information into Log File
GHSA-2hjr-fg6c-v2h6
Unauthorized access to Class instance in Jinjava
GHSA-2hjq-rgfg-v4rj
Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.
GHSA-2hjm-r8h9-f78j
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.
GHSA-2hjm-gpw3-28qp
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
GHSA-2hjm-64qm-49pp
Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
GHSA-2hjm-52g5-36gm
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.
GHSA-2hjh-495w-hmxc
Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
GHSA-2hjg-p8gh-97px
Secure Boot Security Feature Bypass Vulnerability
GHSA-2hjg-g7x8-jf42
IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.
GHSA-2hjg-83v5-q3mf
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
GHSA-2hjg-246p-2f5p
An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.
GHSA-2hjc-v6h4-434p
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2hjx-qmr7-gg4r An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call | 0% Низкий | почти 4 года назад | ||
GHSA-2hjx-g8mm-qjgv Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-2hjw-jh9v-m769 Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175. | 4% Низкий | больше 3 лет назад | ||
GHSA-2hjw-hf33-2w8v Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field. | 1% Низкий | почти 4 года назад | ||
GHSA-2hjw-h4fr-9x35 Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact. | 0% Низкий | почти 4 года назад | ||
GHSA-2hjv-5gg5-2v4c Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-2hjr-wwf2-rh3g Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745. | 1% Низкий | больше 3 лет назад | ||
GHSA-2hjr-vmf3-xwvp Elasticsearch Insertion of Sensitive Information into Log File | CVSS3: 5.2 | 1% Низкий | больше 1 года назад | |
GHSA-2hjr-fg6c-v2h6 Unauthorized access to Class instance in Jinjava | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-2hjq-rgfg-v4rj Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address. | 0% Низкий | почти 4 года назад | ||
GHSA-2hjm-r8h9-f78j A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability. | CVSS3: 9.1 | 5% Низкий | больше 3 лет назад | |
GHSA-2hjm-gpw3-28qp SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2hjm-64qm-49pp Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2hjm-52g5-36gm FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication. | CVSS3: 6.2 | 0% Низкий | около 1 месяца назад | |
GHSA-2hjh-495w-hmxc Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts | 3% Низкий | около 1 года назад | ||
GHSA-2hjg-p8gh-97px Secure Boot Security Feature Bypass Vulnerability | CVSS3: 8 | 1% Низкий | больше 1 года назад | |
GHSA-2hjg-g7x8-jf42 IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2hjg-83v5-q3mf A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-2hjg-246p-2f5p An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution. | CVSS3: 8.8 | 4% Низкий | почти 4 года назад | |
GHSA-2hjc-v6h4-434p A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186. | CVSS3: 5.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу