Количество 315 253
Количество 315 253
GHSA-2943-53pm-phm4
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
GHSA-2943-4gp2-qhj2
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
GHSA-2942-p8v5-q78c
Windows Kerberos Elevation of Privilege Vulnerability.
GHSA-2942-jp7w-55rc
An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field.
GHSA-293x-x4gc-p56j
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.
GHSA-293x-mf2v-87jf
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
GHSA-293x-92j8-gvrh
Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.
GHSA-293w-8h49-x8x8
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.
GHSA-293v-5329-36wp
MCMS vulnerable to arbitrary code execution via crafted thumbnail
GHSA-293v-32vx-9g86
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.
GHSA-293r-f52g-2w34
Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.
GHSA-293r-4r95-pff2
The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.
GHSA-293q-vg2m-m48p
SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php.
GHSA-293q-m4h6-56g9
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.
GHSA-293q-jm6v-g4pw
The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors.
GHSA-293p-8p8x-wx39
SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.
GHSA-293m-v274-vgh4
The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-293m-rx8m-gh7h
MyBB 1.8.19 has XSS in the resetpassword function.
GHSA-293m-43xj-42h4
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.
GHSA-293j-x829-fj24
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2943-53pm-phm4 Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | 0% Низкий | больше 3 лет назад | ||
GHSA-2943-4gp2-qhj2 Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-2942-p8v5-q78c Windows Kerberos Elevation of Privilege Vulnerability. | CVSS3: 8.8 | 8% Низкий | около 4 лет назад | |
GHSA-2942-jp7w-55rc An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field. | CVSS3: 8.8 | 0% Низкий | почти 2 года назад | |
GHSA-293x-x4gc-p56j Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC. | 29% Средний | почти 4 года назад | ||
GHSA-293x-mf2v-87jf A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL. | 0% Низкий | больше 3 лет назад | ||
GHSA-293x-92j8-gvrh Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access. | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-293w-8h49-x8x8 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-293v-5329-36wp MCMS vulnerable to arbitrary code execution via crafted thumbnail | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-293v-32vx-9g86 D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload. | CVSS3: 9.8 | 4% Низкий | около 2 лет назад | |
GHSA-293r-f52g-2w34 Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users. | 0% Низкий | почти 4 года назад | ||
GHSA-293r-4r95-pff2 The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges. | 0% Низкий | больше 3 лет назад | ||
GHSA-293q-vg2m-m48p SeaCMS 6.56 allows remote authenticated administrators to execute arbitrary PHP code via a crafted token field to admin/admin_ping.php, which interacts with data/admin/ping.php. | CVSS3: 7.2 | 1% Низкий | больше 3 лет назад | |
GHSA-293q-m4h6-56g9 OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
GHSA-293q-jm6v-g4pw The Revslider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg upload in all versions up to, and including, 6.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure revslider can be extended to authors. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-293p-8p8x-wx39 SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue. | 0% Низкий | больше 3 лет назад | ||
GHSA-293m-v274-vgh4 The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' shortcode in all versions up to, and including, 1.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 8 месяцев назад | |
GHSA-293m-rx8m-gh7h MyBB 1.8.19 has XSS in the resetpassword function. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-293m-43xj-42h4 Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf. | 0% Низкий | больше 3 лет назад | ||
GHSA-293j-x829-fj24 The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу