Количество 314 078
Количество 314 078
GHSA-226c-wpq4-r9cj
SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
GHSA-226c-v4c5-7xv2
The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2269-968q-6hcq
Memory corruption due to improper access control in Qualcomm IPC.
GHSA-2268-w43v-j544
Cross-Site Request Forgery (CSRF) in stitionai/devika
GHSA-2268-rqjm-gx38
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
GHSA-2268-hc24-w7pm
Azure Network Watcher Agent Security Feature Bypass Vulnerability.
GHSA-2268-98wh-qfhf
JLine vulnerable to out of memory error
GHSA-2268-76c3-x85m
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
GHSA-2267-xqcf-gw2m
FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
GHSA-2267-x99j-hcv3
Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.
GHSA-2267-87gq-vw4p
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
GHSA-2267-86vq-8f86
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.
GHSA-2266-6m7r-fxww
Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1.
GHSA-2266-54fx-rmrv
Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.
GHSA-2265-g92x-3448
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allows PHP Local File Inclusion.This issue affects Athos: from n/a through <= 1.9.
GHSA-2264-q7fx-w4x7
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.
GHSA-2264-54r3-3rjm
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
GHSA-2263-jwgm-wv97
Showdoc XSS Vulnerability
GHSA-2263-gvv9-23vp
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
GHSA-2263-7263-q848
The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0846.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-226c-wpq4-r9cj SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-226c-v4c5-7xv2 The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 29 дней назад | |
GHSA-2269-968q-6hcq Memory corruption due to improper access control in Qualcomm IPC. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-2268-w43v-j544 Cross-Site Request Forgery (CSRF) in stitionai/devika | CVSS3: 8.8 | больше 1 года назад | ||
GHSA-2268-rqjm-gx38 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. | CVSS3: 5.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2268-hc24-w7pm Azure Network Watcher Agent Security Feature Bypass Vulnerability. | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
GHSA-2268-98wh-qfhf JLine vulnerable to out of memory error | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-2268-76c3-x85m An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-2267-xqcf-gw2m FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload | 0% Низкий | около 1 месяца назад | ||
GHSA-2267-x99j-hcv3 Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4. | CVSS3: 9.8 | 0% Низкий | 11 месяцев назад | |
GHSA-2267-87gq-vw4p In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203 | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-2267-86vq-8f86 A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-2266-6m7r-fxww Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1. | 0% Низкий | больше 3 лет назад | ||
GHSA-2266-54fx-rmrv Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-2265-g92x-3448 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allows PHP Local File Inclusion.This issue affects Athos: from n/a through <= 1.9. | CVSS3: 8.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-2264-q7fx-w4x7 Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script. | 66% Средний | больше 3 лет назад | ||
GHSA-2264-54r3-3rjm A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695. | 35% Средний | почти 4 года назад | ||
GHSA-2263-jwgm-wv97 Showdoc XSS Vulnerability | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2263-gvv9-23vp The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection. | 2% Низкий | почти 4 года назад | ||
GHSA-2263-7263-q848 The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0846. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу