Количество 323 805
Количество 323 805
GHSA-26r4-vjwg-4pqh
Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php.
GHSA-26r4-j8xv-5q4j
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
GHSA-26r4-gcg8-rjjp
A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-26r4-c2j9-3fcx
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.
GHSA-26r4-3m3w-c772
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.
GHSA-26r3-pw5g-9v53
The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-26r2-pm58-r4jr
Windows MSHTML Platform Spoofing Vulnerability
GHSA-26r2-c5w2-92vj
The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.
GHSA-26r2-6q54-995j
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.
GHSA-26qx-fmxx-pg6h
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
GHSA-26qx-4m49-6cfr
wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability
GHSA-26qv-p8cr-jxp5
External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.
GHSA-26qv-cc62-952x
Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.
GHSA-26qv-3573-wxg2
A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.
GHSA-26qr-qf74-v2w4
Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.
GHSA-26qr-hrpr-gcj8
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
GHSA-26qr-5f59-55qh
Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.
GHSA-26qr-26wf-xv6x
A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.
GHSA-26qq-h2w9-r3wv
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.
GHSA-26qq-9jw6-r5h4
Intesync Solismed 3.3sp has Incorrect Access Control.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-26r4-vjwg-4pqh Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the update_options action to wp-admin/admin-ajax.php. | 0% Низкий | почти 4 года назад | ||
GHSA-26r4-j8xv-5q4j Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag. | 19% Средний | почти 4 года назад | ||
GHSA-26r4-gcg8-rjjp A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | 11 месяцев назад | |
GHSA-26r4-c2j9-3fcx SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression. | 1% Низкий | почти 4 года назад | ||
GHSA-26r4-3m3w-c772 Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter. | 6% Низкий | почти 4 года назад | ||
GHSA-26r3-pw5g-9v53 The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-26r2-pm58-r4jr Windows MSHTML Platform Spoofing Vulnerability | CVSS3: 6.5 | 18% Средний | больше 1 года назад | |
GHSA-26r2-c5w2-92vj The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-26r2-6q54-995j Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-26qx-fmxx-pg6h Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-26qx-4m49-6cfr wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-26qv-p8cr-jxp5 External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 52% Средний | 10 месяцев назад | |
GHSA-26qv-cc62-952x Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-26qv-3573-wxg2 A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-26qr-qf74-v2w4 Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory. | 0% Низкий | почти 4 года назад | ||
GHSA-26qr-hrpr-gcj8 A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | CVSS3: 6.3 | 1% Низкий | 2 месяца назад | |
GHSA-26qr-5f59-55qh Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-26qr-26wf-xv6x A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges. | 0% Низкий | 14 дней назад | ||
GHSA-26qq-h2w9-r3wv This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983. | CVSS3: 7 | 0% Низкий | почти 4 года назад | |
GHSA-26qq-9jw6-r5h4 Intesync Solismed 3.3sp has Incorrect Access Control. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу