Количество 375 453
Количество 375 453
GHSA-4vf7-8qf6-f3f9
A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name of the patch is fb6fae2f8a9b146471450b5b0281046a17d1ac8d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220204.
GHSA-4vf6-mq7w-3hp6
Zend_Filter_StripTags vulnerable to Cross-site Scripting when comments allowed
GHSA-4vf6-j45c-9rc5
The Horoscopes and Dreams (aka com.horoscopesanddreams) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4vf6-f9c7-q6rp
A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.
GHSA-4vf6-2rmx-fgqx
Gila CMS SQL Injection vulnerability
GHSA-4vf6-2fhm-2c5g
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.
GHSA-4vf5-wq63-5f76
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
GHSA-4vf5-v3wq-vqr9
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
GHSA-4vf4-qmvg-mh7h
Cookie Prefix Spoofing in CGI::Cookie.parse
GHSA-4vf4-9x77-q598
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.
GHSA-4vf4-955g-vxp2
OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration
GHSA-4vf3-h7wh-ppjc
A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.
GHSA-4vf3-fc4g-3xvj
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions.
GHSA-4vf3-57vh-hmm8
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
GHSA-4vf2-qfg3-7598
symfony/validator XML Entity Expansion vulnerability
GHSA-4vf2-hvg4-5qq2
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
GHSA-4vf2-cm23-rf4c
Incorrect Authorization in Jenkins Gerrit Trigger Plugin
GHSA-4vf2-4xcg-65cx
Division by 0 in `Conv2D`
GHSA-4vcx-3pj3-44m7
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
GHSA-4vcw-h879-447q
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4vf7-8qf6-f3f9 A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name of the patch is fb6fae2f8a9b146471450b5b0281046a17d1ac8d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220204. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-4vf6-mq7w-3hp6 Zend_Filter_StripTags vulnerable to Cross-site Scripting when comments allowed | CVSS3: 6.1 | больше 2 лет назад | ||
GHSA-4vf6-j45c-9rc5 The Horoscopes and Dreams (aka com.horoscopesanddreams) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4vf6-f9c7-q6rp A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-4vf6-2rmx-fgqx Gila CMS SQL Injection vulnerability | CVSS3: 3.8 | 1% Низкий | больше 2 лет назад | |
GHSA-4vf6-2fhm-2c5g Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark. | 9% Низкий | больше 4 лет назад | ||
GHSA-4vf5-wq63-5f76 Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. | 1% Низкий | больше 4 лет назад | ||
GHSA-4vf5-v3wq-vqr9 Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | CVSS3: 9.8 | 92% Критический | больше 4 лет назад | |
GHSA-4vf4-qmvg-mh7h Cookie Prefix Spoofing in CGI::Cookie.parse | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4vf4-9x77-q598 Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files. | 0% Низкий | больше 4 лет назад | ||
GHSA-4vf4-955g-vxp2 OroCommerce Cross site scripting vulnerability during shipping rule editing for UPS integration | CVSS3: 6.9 | 0% Низкий | почти 4 года назад | |
GHSA-4vf3-h7wh-ppjc A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4vf3-fc4g-3xvj Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-4vf3-57vh-hmm8 Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-4vf2-qfg3-7598 symfony/validator XML Entity Expansion vulnerability | CVSS3: 7.5 | больше 2 лет назад | ||
GHSA-4vf2-hvg4-5qq2 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-4vf2-cm23-rf4c Incorrect Authorization in Jenkins Gerrit Trigger Plugin | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-4vf2-4xcg-65cx Division by 0 in `Conv2D` | CVSS3: 2.5 | 0% Низкий | больше 5 лет назад | |
GHSA-4vcx-3pj3-44m7 Dosage vulnerable to a Directory Traversal through crafted HTTP responses | CVSS3: 8.8 | 0% Низкий | 11 месяцев назад | |
GHSA-4vcw-h879-447q If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. | CVSS3: 8.6 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу