Количество 313 368
Количество 313 368
GHSA-2564-4rf9-wv93
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.
GHSA-2563-x4h3-pq75
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.
GHSA-2563-r73r-7cq9
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
GHSA-2563-fp9c-mgm8
Moodle Session Fixation vulnerability
GHSA-2563-9f8c-7cw3
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
GHSA-2563-83p7-f34p
Malicious Package in requestt
GHSA-255x-mvhm-3947
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
GHSA-255w-87rh-rg44
Cross-site Scripting via uploaded SVG
GHSA-255v-qv84-29p5
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
GHSA-255v-qpcm-wc95
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
GHSA-255v-hc9m-54wv
Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.
GHSA-255v-grg6-24pg
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
GHSA-255v-ffqg-5w87
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
GHSA-255r-pghp-r5wh
Malicious Package in hdeky
GHSA-255r-f4p7-p9r5
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA-255r-3prx-mf99
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
GHSA-255q-f9p7-jxj6
Microsoft SharePoint Server Spoofing Vulnerability
GHSA-255p-hfwr-9qm4
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.
GHSA-255p-hfc6-whjx
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.
GHSA-255m-x7w5-9w65
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2564-4rf9-wv93 Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation. | 0% Низкий | больше 3 лет назад | ||
GHSA-2563-x4h3-pq75 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2563-r73r-7cq9 Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | CVSS3: 9.8 | 17% Средний | почти 4 года назад | |
GHSA-2563-fp9c-mgm8 Moodle Session Fixation vulnerability | CVSS3: 9.8 | 21% Средний | почти 3 года назад | |
GHSA-2563-9f8c-7cw3 PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | 9% Низкий | почти 4 года назад | ||
GHSA-2563-83p7-f34p Malicious Package in requestt | CVSS3: 9.8 | больше 5 лет назад | ||
GHSA-255x-mvhm-3947 The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-255w-87rh-rg44 Cross-site Scripting via uploaded SVG | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
GHSA-255v-qv84-29p5 DragonFly's manager generates mTLS certificates for arbitrary IP addresses | 0% Низкий | 5 месяцев назад | ||
GHSA-255v-qpcm-wc95 Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number. | 0% Низкий | больше 3 лет назад | ||
GHSA-255v-hc9m-54wv Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1. | CVSS3: 5.4 | 0% Низкий | около 2 месяцев назад | |
GHSA-255v-grg6-24pg MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | CVSS3: 9.8 | 10% Низкий | больше 2 лет назад | |
GHSA-255v-ffqg-5w87 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-255r-pghp-r5wh Malicious Package in hdeky | CVSS3: 9.1 | больше 5 лет назад | ||
GHSA-255r-f4p7-p9r5 Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 0% Низкий | больше 3 лет назад | ||
GHSA-255r-3prx-mf99 `rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8 | почти 3 года назад | |||
GHSA-255q-f9p7-jxj6 Microsoft SharePoint Server Spoofing Vulnerability | CVSS3: 8 | 0% Низкий | больше 2 лет назад | |
GHSA-255p-hfwr-9qm4 This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information. | CVSS3: 4.4 | 0% Низкий | больше 3 лет назад | |
GHSA-255p-hfc6-whjx This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021. | 3% Низкий | больше 3 лет назад | ||
GHSA-255m-x7w5-9w65 Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | CVSS3: 9.8 | 0% Низкий | 12 месяцев назад |
Уязвимостей на страницу