Количество 313 854
Количество 313 854
GHSA-2425-r3xx-w4v7
carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).
GHSA-2425-64hv-g99c
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay allows Stored XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.5.11.
GHSA-2425-2c7p-9cg9
A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as critical. This issue affects the function run_query of the file /query_runner/python.py of the component getattr Handler. The manipulation leads to sandbox issue. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2424-x5j2-7rx4
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.
GHSA-2424-v4cf-7rr6
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
GHSA-2424-q483-wgpq
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
GHSA-2424-8qh4-3ggg
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges.
GHSA-2424-5f9c-864m
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
GHSA-2424-29jp-qgw2
MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.
GHSA-2423-333r-g3m8
Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action.
GHSA-2423-2c9w-8vgr
File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is parsed. For example, given a string like: data:image/html;base64,PGh0bWw+PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPjwvaHRtbD4= the content after the comma is extracted and decoded using Base64.getDecoder().decode(). The substring from the 11th character up to the first occurrence of a semicolon (;) is assigned to the suffix variable (representing the file extension). The decoded content is then written to a file. However, the file extension is not validated, and since this functionality is exposed to the frontend, it poses significant security risks.
GHSA-2422-39jf-m5cr
The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4388, CVE-2016-4389, and CVE-2016-4390.
GHSA-23xx-r9hm-q9g9
A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240867.
GHSA-23xw-ccm5-g9pf
baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.
GHSA-23xv-rh65-95rq
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-23xv-3xmf-w354
Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).
GHSA-23xr-9xxr-vg3c
Improper authorization vulnerability in Jenkins Mesos Plugin
GHSA-23xp-j737-282v
Path Traversal in takeapeek
GHSA-23xp-gwgx-qmr4
The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385.
GHSA-23xp-c8gg-3439
The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2425-r3xx-w4v7 carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System). | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2425-64hv-g99c Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay allows Stored XSS.This issue affects WP-Lister Lite for eBay: from n/a through 3.5.11. | CVSS3: 5.9 | 0% Низкий | почти 2 года назад | |
GHSA-2425-2c7p-9cg9 A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as critical. This issue affects the function run_query of the file /query_runner/python.py of the component getattr Handler. The manipulation leads to sandbox issue. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.5 | 0% Низкий | 8 месяцев назад | |
GHSA-2424-x5j2-7rx4 The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz. | 17% Средний | больше 3 лет назад | ||
GHSA-2424-v4cf-7rr6 Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2424-q483-wgpq Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2424-8qh4-3ggg SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissions for this file, which allows local users to gain privileges. | 0% Низкий | почти 4 года назад | ||
GHSA-2424-5f9c-864m Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php. | 0% Низкий | почти 4 года назад | ||
GHSA-2424-29jp-qgw2 MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb. | 0% Низкий | почти 4 года назад | ||
GHSA-2423-333r-g3m8 Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action. | 1% Низкий | больше 3 лет назад | ||
GHSA-2423-2c9w-8vgr File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is parsed. For example, given a string like: data:image/html;base64,PGh0bWw+PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPjwvaHRtbD4= the content after the comma is extracted and decoded using Base64.getDecoder().decode(). The substring from the 11th character up to the first occurrence of a semicolon (;) is assigned to the suffix variable (representing the file extension). The decoded content is then written to a file. However, the file extension is not validated, and since this functionality is exposed to the frontend, it poses significant security risks. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-2422-39jf-m5cr The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4388, CVE-2016-4389, and CVE-2016-4390. | CVSS3: 8.1 | 2% Низкий | больше 3 лет назад | |
GHSA-23xx-r9hm-q9g9 A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240867. | CVSS3: 6.3 | 0% Низкий | больше 2 лет назад | |
GHSA-23xw-ccm5-g9pf baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-23xv-rh65-95rq SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-23xv-3xmf-w354 Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument). | 0% Низкий | почти 4 года назад | ||
GHSA-23xr-9xxr-vg3c Improper authorization vulnerability in Jenkins Mesos Plugin | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-23xp-j737-282v Path Traversal in takeapeek | CVSS3: 5.3 | 0% Низкий | около 7 лет назад | |
GHSA-23xp-gwgx-qmr4 The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-23xp-c8gg-3439 The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу