Количество 326 827
Количество 326 827
GHSA-2hw5-388c-g7xj
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
GHSA-2hw3-wmq2-hxf7
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
GHSA-2hw3-rfjc-q8m6
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.
GHSA-2hw3-h8qx-hqqp
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
GHSA-2hw3-28v7-q78p
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
GHSA-2hw2-hc6g-cv7v
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
GHSA-2hw2-h3mf-c2j9
Moodle open redirect vulnerability
GHSA-2hw2-7jq8-w9vp
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
GHSA-2hw2-62cp-p9p7
Access control bypass in Apache ZooKeeper
GHSA-2hvx-m86j-h9m3
Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.
GHSA-2hvx-9r8j-qvph
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-2hvx-93c2-p928
** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.
GHSA-2hvw-r4rp-mjpp
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
GHSA-2hvv-h4pw-wcm2
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
GHSA-2hvr-h6gw-qrxp
Cargo extracting malicious crates can fill the file system
GHSA-2hvr-43xf-39rx
Not used in 2022
GHSA-2hvq-vmfm-c497
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.
GHSA-2hvm-7cm7-f4p9
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
GHSA-2hvj-wgq7-vx3c
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.
GHSA-2hvj-p59v-p559
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2hw5-388c-g7xj Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-2hw3-wmq2-hxf7 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-2hw3-rfjc-q8m6 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4. | CVSS3: 9 | 0% Низкий | 6 месяцев назад | |
GHSA-2hw3-h8qx-hqqp OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-2hw3-28v7-q78p Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability." | 48% Средний | почти 4 года назад | ||
GHSA-2hw2-hc6g-cv7v IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. | CVSS3: 9.8 | 0% Низкий | 6 месяцев назад | |
GHSA-2hw2-h3mf-c2j9 Moodle open redirect vulnerability | CVSS3: 7.4 | 0% Низкий | почти 4 года назад | |
GHSA-2hw2-7jq8-w9vp The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | 75% Высокий | больше 4 лет назад | ||
GHSA-2hw2-62cp-p9p7 Access control bypass in Apache ZooKeeper | CVSS3: 5.9 | 0% Низкий | почти 7 лет назад | |
GHSA-2hvx-m86j-h9m3 Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function. | 23% Средний | почти 4 года назад | ||
GHSA-2hvx-9r8j-qvph The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-2hvx-93c2-p928 ** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity. | CVSS3: 8.6 | 0% Низкий | больше 2 лет назад | |
GHSA-2hvw-r4rp-mjpp Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-2hvv-h4pw-wcm2 The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands. | 0% Низкий | почти 4 года назад | ||
GHSA-2hvr-h6gw-qrxp Cargo extracting malicious crates can fill the file system | CVSS3: 4.2 | 0% Низкий | больше 3 лет назад | |
GHSA-2hvr-43xf-39rx Not used in 2022 | около 3 лет назад | |||
GHSA-2hvq-vmfm-c497 A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2hvm-7cm7-f4p9 The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-2hvj-wgq7-vx3c WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files. | 0% Низкий | почти 4 года назад | ||
GHSA-2hvj-p59v-p559 The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу