Количество 315 253
Количество 315 253
GHSA-297g-cjpm-qw2x
Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.
GHSA-297g-9xq6-v8vj
Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.
GHSA-297g-9658-43jh
Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
GHSA-297g-672r-7mgh
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
GHSA-297g-44c7-436q
Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.
GHSA-297f-r9w7-w492
Magento Improper input validation vulnerability
GHSA-297f-24c2-wwfv
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
GHSA-297c-p9xm-3rhf
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.
GHSA-297c-8rmr-xrxf
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
GHSA-297c-34f3-r565
feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.
GHSA-2979-3fv7-8r3w
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.
GHSA-2978-89p5-cxgh
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.
GHSA-2978-6549-pf4r
SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.
GHSA-2977-w3fj-rc33
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
GHSA-2977-ph22-g7f6
The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-2977-c3c9-wqxf
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.
GHSA-2977-6mrh-4c63
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
GHSA-2977-5php-6789
Erxes Path Traversal vulnerability
GHSA-2976-mg74-v97h
Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.
GHSA-2976-6mfc-xmp6
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-297g-cjpm-qw2x Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2. | CVSS3: 5.3 | 2% Низкий | 10 месяцев назад | |
GHSA-297g-9xq6-v8vj Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-297g-9658-43jh Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213. | 0% Низкий | больше 3 лет назад | ||
GHSA-297g-672r-7mgh Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-297g-44c7-436q Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user. | 4% Низкий | почти 4 года назад | ||
GHSA-297f-r9w7-w492 Magento Improper input validation vulnerability | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-297f-24c2-wwfv Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-297c-p9xm-3rhf A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-297c-8rmr-xrxf Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs. | 0% Низкий | почти 4 года назад | ||
GHSA-297c-34f3-r565 feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php. | 0% Низкий | почти 4 года назад | ||
GHSA-2979-3fv7-8r3w In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-2978-89p5-cxgh An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2978-6549-pf4r SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-2977-w3fj-rc33 Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-2977-ph22-g7f6 The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-2977-c3c9-wqxf Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-2977-6mrh-4c63 MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-2977-5php-6789 Erxes Path Traversal vulnerability | 0% Низкий | 8 месяцев назад | ||
GHSA-2976-mg74-v97h Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2976-6mfc-xmp6 user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу