Количество 324 556
Количество 324 556
GHSA-285c-r388-3j3j
A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-285c-6wq3-96wh
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.
GHSA-2859-fc3x-94xw
Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-2859-f9hx-gvcp
SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.
GHSA-2859-5gr5-x7f5
Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.
GHSA-2859-3xrw-r77c
D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.
GHSA-2859-2jv7-892h
Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676.
GHSA-2859-2hr6-f86v
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
GHSA-2858-xg23-26fp
OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots
GHSA-2858-jrxx-h689
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-2858-8cfx-69m9
XWiki Platform: Remote code execution as guest via DatabaseSearch
GHSA-2856-xf2f-6vrf
Liferay Portal vulnerable to cross-site scripting in the related asset selector
GHSA-2856-c9gx-h7rp
Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.
GHSA-2856-5p3x-qmfp
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.
GHSA-2856-2658-h48j
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.
GHSA-2854-jq38-8grq
Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.
GHSA-2853-mpq7-6f9j
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /goform/formConfigDnsFilterGlobal. Such manipulation of the argument timeRangeName leads to buffer overflow. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2853-hf2g-9843
PHPOffice Common Improper Restriction of XML External Entity Reference
GHSA-2853-84mf-g278
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later
GHSA-284w-4f63-96hj
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCua61331.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-285c-r388-3j3j A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 9 месяцев назад | |
GHSA-285c-6wq3-96wh Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file. | CVSS3: 9.8 | 3% Низкий | почти 4 года назад | |
GHSA-2859-fc3x-94xw Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1% Низкий | почти 4 года назад | ||
GHSA-2859-f9hx-gvcp SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-2859-5gr5-x7f5 Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device. | 0% Низкий | почти 4 года назад | ||
GHSA-2859-3xrw-r77c D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root. | CVSS3: 8.8 | 1% Низкий | почти 2 года назад | |
GHSA-2859-2jv7-892h Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676. | 0% Низкий | почти 4 года назад | ||
GHSA-2859-2hr6-f86v In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages. | CVSS3: 9.8 | 94% Критический | почти 4 года назад | |
GHSA-2858-xg23-26fp OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots | CVSS3: 5.5 | около 1 месяца назад | ||
GHSA-2858-jrxx-h689 SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-2858-8cfx-69m9 XWiki Platform: Remote code execution as guest via DatabaseSearch | CVSS3: 10 | 94% Критический | почти 2 года назад | |
GHSA-2856-xf2f-6vrf Liferay Portal vulnerable to cross-site scripting in the related asset selector | 0% Низкий | 6 месяцев назад | ||
GHSA-2856-c9gx-h7rp Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. | 1% Низкий | почти 4 года назад | ||
GHSA-2856-5p3x-qmfp Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650. | CVSS3: 8.8 | 47% Средний | почти 4 года назад | |
GHSA-2856-2658-h48j A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data. | CVSS3: 7.1 | 0% Низкий | почти 4 года назад | |
GHSA-2854-jq38-8grq Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-2853-mpq7-6f9j A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /goform/formConfigDnsFilterGlobal. Such manipulation of the argument timeRangeName leads to buffer overflow. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.7 | 0% Низкий | 4 месяца назад | |
GHSA-2853-hf2g-9843 PHPOffice Common Improper Restriction of XML External Entity Reference | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-2853-84mf-g278 An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-284w-4f63-96hj Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCua61331. | 5% Низкий | почти 4 года назад |
Уязвимостей на страницу