Количество 314 928
Количество 314 928
GHSA-226m-fqfj-v6xp
Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.
GHSA-226j-3v4h-8cg4
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
GHSA-226h-qrg4-8236
Stored XSS vulnerability in chosen-views-tabbar Plugin
GHSA-226h-j848-vv7w
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-226h-h99r-j24r
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-226h-cxv5-p8qg
The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-226h-772w-v9vj
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).
GHSA-226h-2qfh-4hf8
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
GHSA-226f-28jj-g35j
A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-226c-wpq4-r9cj
SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
GHSA-226c-v4c5-7xv2
The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2269-968q-6hcq
Memory corruption due to improper access control in Qualcomm IPC.
GHSA-2268-w43v-j544
Cross-Site Request Forgery (CSRF) in stitionai/devika
GHSA-2268-rqjm-gx38
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
GHSA-2268-hc24-w7pm
Azure Network Watcher Agent Security Feature Bypass Vulnerability.
GHSA-2268-98wh-qfhf
JLine vulnerable to out of memory error
GHSA-2268-76c3-x85m
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
GHSA-2267-xqcf-gw2m
FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
GHSA-2267-x99j-hcv3
Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.
GHSA-2267-87gq-vw4p
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-226m-fqfj-v6xp Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-226j-3v4h-8cg4 Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-226h-qrg4-8236 Stored XSS vulnerability in chosen-views-tabbar Plugin | CVSS3: 8 | 0% Низкий | больше 3 лет назад | |
GHSA-226h-j848-vv7w A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | 8 месяцев назад | |
GHSA-226h-h99r-j24r Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
GHSA-226h-cxv5-p8qg The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-226h-772w-v9vj Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address). | 3% Низкий | больше 3 лет назад | ||
GHSA-226h-2qfh-4hf8 Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-226f-28jj-g35j A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
GHSA-226c-wpq4-r9cj SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-226c-v4c5-7xv2 The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 1 месяца назад | |
GHSA-2269-968q-6hcq Memory corruption due to improper access control in Qualcomm IPC. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-2268-w43v-j544 Cross-Site Request Forgery (CSRF) in stitionai/devika | CVSS3: 8.8 | больше 1 года назад | ||
GHSA-2268-rqjm-gx38 IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. | CVSS3: 5.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2268-hc24-w7pm Azure Network Watcher Agent Security Feature Bypass Vulnerability. | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
GHSA-2268-98wh-qfhf JLine vulnerable to out of memory error | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-2268-76c3-x85m An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-2267-xqcf-gw2m FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload | 0% Низкий | около 1 месяца назад | ||
GHSA-2267-x99j-hcv3 Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4. | CVSS3: 9.8 | 0% Низкий | 12 месяцев назад | |
GHSA-2267-87gq-vw4p In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203 | CVSS3: 5.5 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу