Количество 313 854
Количество 313 854
GHSA-24xc-5f2v-5mc5
A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-24xc-3gmc-877f
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
GHSA-24x9-9gx2-3g25
The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
GHSA-24x8-vf4r-m3v5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.
GHSA-24x8-275w-hwpr
The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data
GHSA-24x7-gxr3-5r7r
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
GHSA-24x7-c4mf-44m6
A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-24x7-8mv3-v5xj
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.
GHSA-24x6-8c7m-hv3f
Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
GHSA-24x5-c472-vx8w
A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service.
GHSA-24x4-hpq6-x4j9
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.
GHSA-24x4-6qmh-88qg
Use after free in `DecodePng` kernel
GHSA-24x4-44mg-fffp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.
GHSA-24x2-jv4m-57w2
Rejected reason: Not used
GHSA-24wx-mghc-gchm
A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.
GHSA-24wx-m9jq-x9f7
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
GHSA-24ww-mc5x-xc43
Man-in-the-middle attack in Apache Cassandra
GHSA-24ww-hqf6-2c58
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-24ww-94h4-w44f
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
GHSA-24wv-qqjw-rp9w
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-24xc-5f2v-5mc5 A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | 8 месяцев назад | |
GHSA-24xc-3gmc-877f The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-24x9-9gx2-3g25 The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting | CVSS3: 6.1 | 5% Низкий | больше 3 лет назад | |
GHSA-24x8-vf4r-m3v5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
GHSA-24x8-275w-hwpr The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-24x7-gxr3-5r7r The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-24x7-c4mf-44m6 A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.5 | 10 месяцев назад | ||
GHSA-24x7-8mv3-v5xj A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276. | CVSS3: 2.4 | 0% Низкий | почти 3 года назад | |
GHSA-24x6-8c7m-hv3f Heap OOB read in TFLite's implementation of `Minimum` or `Maximum` | CVSS3: 2.5 | 0% Низкий | больше 4 лет назад | |
GHSA-24x5-c472-vx8w A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-24x4-hpq6-x4j9 Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter. | 3% Низкий | почти 4 года назад | ||
GHSA-24x4-6qmh-88qg Use after free in `DecodePng` kernel | CVSS3: 7.6 | 0% Низкий | почти 4 года назад | |
GHSA-24x4-44mg-fffp Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/. | 7% Низкий | больше 3 лет назад | ||
GHSA-24x2-jv4m-57w2 Rejected reason: Not used | около 1 месяца назад | |||
GHSA-24wx-mghc-gchm A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-24wx-m9jq-x9f7 Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11. | CVSS3: 9.8 | 0% Низкий | 27 дней назад | |
GHSA-24ww-mc5x-xc43 Man-in-the-middle attack in Apache Cassandra | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад | |
GHSA-24ww-hqf6-2c58 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | около 1 месяца назад | |||
GHSA-24ww-94h4-w44f Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors. | 1% Низкий | почти 4 года назад | ||
GHSA-24wv-qqjw-rp9w Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access. | CVSS3: 4.6 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу