Количество 376 080
Количество 376 080
GHSA-4x38-3vm4-2pv5
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-4x37-wc67-gqjf
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
GHSA-4x37-hw65-52w8
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
GHSA-4x37-644q-76x6
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
GHSA-4x37-5rh2-hp8c
node-opencv is malware
GHSA-4x36-p66f-4f99
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
GHSA-4x35-vr82-xvj6
SQL Injection in AssetController
GHSA-4x35-v2c7-mwxv
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.
GHSA-4x35-gq92-53gx
Insertion of Sensitive Information Into Sent Data vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Retrieve Embedded Sensitive Data. This issue affects Hesabfa Accounting: from n/a through 2.2.4.
GHSA-4x35-7764-9cfw
UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.
GHSA-4x34-x52v-9q9x
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
GHSA-4x34-w43g-2cfc
** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. NOTE: the vendor states "This was a flaw for the developer/debugging devices, and was fixed in production version about 3 years ago."
GHSA-4x34-chg5-mwjj
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4x34-82r8-65cf
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.
GHSA-4x34-22jv-cj7q
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.
GHSA-4x33-wj73-4gxp
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
GHSA-4x33-rw6q-ch5p
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
GHSA-4x33-fm36-xfq9
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
GHSA-4x33-7vp7-cq3r
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.
GHSA-4x33-566w-9pg7
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4x38-3vm4-2pv5 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | около 1 месяца назад | |||
GHSA-4x37-wc67-gqjf MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI. | CVSS3: 5.7 | 0% Низкий | больше 4 лет назад | |
GHSA-4x37-hw65-52w8 Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-4x37-644q-76x6 Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Core Receiving). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Inventory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Inventory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
GHSA-4x37-5rh2-hp8c node-opencv is malware | CVSS3: 7.5 | 1% Низкий | около 8 лет назад | |
GHSA-4x36-p66f-4f99 Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. | 3% Низкий | больше 4 лет назад | ||
GHSA-4x35-vr82-xvj6 SQL Injection in AssetController | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4x35-v2c7-mwxv Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000. | 10% Средний | больше 4 лет назад | ||
GHSA-4x35-gq92-53gx Insertion of Sensitive Information Into Sent Data vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Retrieve Embedded Sensitive Data. This issue affects Hesabfa Accounting: from n/a through 2.2.4. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-4x35-7764-9cfw UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command. | 1% Низкий | больше 4 лет назад | ||
GHSA-4x34-x52v-9q9x An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4x34-w43g-2cfc ** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. NOTE: the vendor states "This was a flaw for the developer/debugging devices, and was fixed in production version about 3 years ago." | 2% Низкий | больше 4 лет назад | ||
GHSA-4x34-chg5-mwjj chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins) | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
GHSA-4x34-82r8-65cf Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources. | CVSS3: 7.7 | 0% Низкий | 23 дня назад | |
GHSA-4x34-22jv-cj7q PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-4x33-wj73-4gxp The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-4x33-rw6q-ch5p Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-4x33-fm36-xfq9 Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4x33-7vp7-cq3r An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4x33-566w-9pg7 GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed. | CVSS3: 6.2 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу