Количество 326 121
Количество 326 121
GHSA-2gh8-gr6x-7q26
SOAPpy vulnerable to XXE attacks
GHSA-2gh7-vr34-cxv5
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode.
GHSA-2gh6-wc3m-g37f
hermes-management is vulnerable to RCE due to Apache commons-jxpath
GHSA-2gh6-8p4x-h863
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
GHSA-2gh4-q9qq-fc54
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.
GHSA-2gh3-rmm4-6rq5
Crash due to uncontrolled recursion in protobuf crate
GHSA-2gh3-6gpq-7rmj
Kofax Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21829.
GHSA-2gh2-2xq4-xqwf
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
GHSA-2ggx-v668-h3cf
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
GHSA-2ggx-jwwc-p8hr
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
GHSA-2ggw-rq7m-r35x
Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.
GHSA-2ggw-q935-g2j9
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.
GHSA-2ggw-fmhw-m4pr
A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. Affected is an unknown function of the file admin-manage-user.php. The manipulation of the argument admin_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259068.
GHSA-2ggw-8gmc-r2gq
Liferay Portal XSS vulnerability via movie parameter in the /html/portal/flash.jsp page
GHSA-2ggv-vfg5-vf2c
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.
GHSA-2ggv-mm3c-gqxm
72crm 9.0 has an Arbitrary file upload vulnerability.
GHSA-2ggv-947x-gfhx
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.
GHSA-2ggr-q5x3-fm96
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device.
GHSA-2ggq-vfcp-gwhj
Cross-Site Scripting in @hapi/boom
GHSA-2ggq-hfx2-5mqh
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2gh8-gr6x-7q26 SOAPpy vulnerable to XXE attacks | 1% Низкий | почти 4 года назад | ||
GHSA-2gh7-vr34-cxv5 SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode. | 0% Низкий | почти 4 года назад | ||
GHSA-2gh6-wc3m-g37f hermes-management is vulnerable to RCE due to Apache commons-jxpath | CVSS3: 9.8 | больше 1 года назад | ||
GHSA-2gh6-8p4x-h863 The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-2gh4-q9qq-fc54 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2gh3-rmm4-6rq5 Crash due to uncontrolled recursion in protobuf crate | 0% Низкий | около 1 года назад | ||
GHSA-2gh3-6gpq-7rmj Kofax Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21829. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад | |
GHSA-2gh2-2xq4-xqwf Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | CVSS3: 8.8 | 40% Средний | почти 4 года назад | |
GHSA-2ggx-v668-h3cf A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device. | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2ggx-jwwc-p8hr Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. | CVSS3: 9.8 | 12% Средний | почти 4 года назад | |
GHSA-2ggw-rq7m-r35x Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file. | CVSS3: 8.8 | 8% Низкий | почти 4 года назад | |
GHSA-2ggw-q935-g2j9 The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request. | 65% Средний | почти 4 года назад | ||
GHSA-2ggw-fmhw-m4pr A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. Affected is an unknown function of the file admin-manage-user.php. The manipulation of the argument admin_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259068. | CVSS3: 6.3 | 0% Низкий | около 2 лет назад | |
GHSA-2ggw-8gmc-r2gq Liferay Portal XSS vulnerability via movie parameter in the /html/portal/flash.jsp page | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-2ggv-vfg5-vf2c A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests. Successful exploit could allow an attacker to execute arbitrary code within the context of the application. | CVSS3: 9.8 | 2% Низкий | почти 4 года назад | |
GHSA-2ggv-mm3c-gqxm 72crm 9.0 has an Arbitrary file upload vulnerability. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2ggv-947x-gfhx Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html. | 0% Низкий | почти 4 года назад | ||
GHSA-2ggr-q5x3-fm96 A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted arguments. A successful exploit could allow the attacker to overwrite or create files with data that is already present in other files that are hosted on the affected device. | CVSS3: 4.4 | 0% Низкий | почти 4 года назад | |
GHSA-2ggq-vfcp-gwhj Cross-Site Scripting in @hapi/boom | CVSS3: 6.5 | больше 5 лет назад | ||
GHSA-2ggq-hfx2-5mqh A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу