Количество 324 758
Количество 324 758
GHSA-28wv-5cj3-9qg6
SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.
GHSA-28wv-3g38-px4r
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors.
GHSA-28wv-3f44-9j22
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-28wr-vmq3-227j
A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-28wr-h897-6hmv
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
GHSA-28wq-pxv7-mr7m
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
GHSA-28wq-p9hh-3w4h
Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.
GHSA-28wp-2xch-xmx5
The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.
GHSA-28wh-pr48-2cq7
iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information.
GHSA-28wh-2mp5-4gp8
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
GHSA-28wg-r79p-3484
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.
GHSA-28wg-8gv4-mpjf
Broken access control in Silverpeas
GHSA-28wg-555g-fr2v
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
GHSA-28wf-q2m6-rjgv
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
GHSA-28wf-jx5m-6fhg
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
GHSA-28wf-973p-g3gx
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
GHSA-28wc-7mwv-p5h3
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
GHSA-28w9-vf5c-mw9p
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.
GHSA-28w9-qhgf-j4rh
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
GHSA-28w9-f394-mqfw
Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28wv-5cj3-9qg6 SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
GHSA-28wv-3g38-px4r The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the (1) Start, (2) PauseAndSave, (3) InsertMarker, and (4) InsertSoundToFBRAtMarker methods, which allows remote attackers to execute arbitrary code via unspecified vectors. | 2% Низкий | почти 4 года назад | ||
GHSA-28wv-3f44-9j22 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-28wr-vmq3-227j A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.5 | 0% Низкий | 8 месяцев назад | |
GHSA-28wr-h897-6hmv Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-28wq-pxv7-mr7m In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | CVSS3: 7.5 | 15% Средний | почти 4 года назад | |
GHSA-28wq-p9hh-3w4h Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 4.8 | 0% Низкий | почти 4 года назад | |
GHSA-28wp-2xch-xmx5 The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416. | 0% Низкий | почти 4 года назад | ||
GHSA-28wh-pr48-2cq7 iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information. | CVSS3: 8.2 | 0% Низкий | 25 дней назад | |
GHSA-28wh-2mp5-4gp8 Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-28wg-r79p-3484 Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-28wg-8gv4-mpjf Broken access control in Silverpeas | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
GHSA-28wg-555g-fr2v If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-28wf-q2m6-rjgv Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability. | CVSS3: 8.2 | 0% Низкий | 10 месяцев назад | |
GHSA-28wf-jx5m-6fhg An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-28wf-973p-g3gx In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. | 0% Низкий | около 4 лет назад | ||
GHSA-28wc-7mwv-p5h3 In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-28w9-vf5c-mw9p E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks. | 0% Низкий | почти 4 года назад | ||
GHSA-28w9-qhgf-j4rh Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-28w9-f394-mqfw Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets. | 8% Низкий | почти 4 года назад |
Уязвимостей на страницу