Количество 325 903
Количество 325 903
GHSA-2fp2-wfm4-76mp
The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.
GHSA-2fp2-v24h-74gp
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.
GHSA-2fp2-f5qv-826q
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.
GHSA-2fmx-fw55-g6jg
Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.
GHSA-2fmx-8p94-cm2g
Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2fmw-vp29-wcgf
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
GHSA-2fmw-p7gw-97jj
A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.
GHSA-2fmv-j5xj-4fmq
Moodle Reveals Student Information Meant To Be Anonymous
GHSA-2fmv-g8v2-32hj
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.
GHSA-2fmv-49qj-83rm
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
GHSA-2fmr-xm36-8jjg
The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.
GHSA-2fmr-2c6h-79j9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.
GHSA-2fmq-75qj-9j34
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
GHSA-2fmp-mw85-gxqw
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device.
GHSA-2fmp-7xwf-wvwr
Arbitrary File Read in Snyk Broker
GHSA-2fmj-pq77-gvj7
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.
GHSA-2fmj-fcp4-f992
Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function
GHSA-2fmh-chfc-392c
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.
GHSA-2fmg-qfp6-p727
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
GHSA-2fmc-hw9p-wg9h
service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2fp2-wfm4-76mp The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990. | 0% Низкий | почти 4 года назад | ||
GHSA-2fp2-v24h-74gp In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD. | 0% Низкий | почти 4 года назад | ||
GHSA-2fp2-f5qv-826q ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-2fmx-fw55-g6jg Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-2fmx-8p94-cm2g Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2fmw-vp29-wcgf ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. | CVSS3: 9.8 | 70% Высокий | почти 4 года назад | |
GHSA-2fmw-p7gw-97jj A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. | CVSS3: 4.9 | 0% Низкий | около 2 месяцев назад | |
GHSA-2fmv-j5xj-4fmq Moodle Reveals Student Information Meant To Be Anonymous | 0% Низкий | почти 4 года назад | ||
GHSA-2fmv-g8v2-32hj In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page. | 0% Низкий | почти 4 года назад | ||
GHSA-2fmv-49qj-83rm novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2fmr-xm36-8jjg The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017. | 1% Низкий | почти 4 года назад | ||
GHSA-2fmr-2c6h-79j9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-2fmq-75qj-9j34 Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module. | 1% Низкий | почти 4 года назад | ||
GHSA-2fmp-mw85-gxqw An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2fmp-7xwf-wvwr Arbitrary File Read in Snyk Broker | CVSS3: 6.5 | 0% Низкий | почти 6 лет назад | |
GHSA-2fmj-pq77-gvj7 The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability. | CVSS3: 6.1 | 24% Средний | почти 3 года назад | |
GHSA-2fmj-fcp4-f992 Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-2fmh-chfc-392c mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data. | CVSS3: 9.8 | 2% Низкий | 11 месяцев назад | |
GHSA-2fmg-qfp6-p727 An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4. | 1% Низкий | почти 4 года назад | ||
GHSA-2fmc-hw9p-wg9h service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу