Количество 322 820
Количество 322 820
GHSA-23fx-r767-q5g7
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
GHSA-23fx-gfqr-cvpx
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through dagor_2025_01_15.
GHSA-23fx-92m6-4f2g
pretalx allows path traversal in HTML export
GHSA-23fw-5352-7h9v
Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant.
GHSA-23fv-pj9m-qvh4
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
GHSA-23fv-m8pv-77j9
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
GHSA-23fr-29gc-hh5j
McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
GHSA-23fq-q7hc-993r
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0
GHSA-23fq-fj6g-jf68
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
GHSA-23fq-26rx-3gc4
Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.
GHSA-23fp-xqj8-q68w
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.
GHSA-23fp-wmqj-rfh4
Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'.
GHSA-23fp-mrfv-cwv4
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.
GHSA-23fp-mccx-jgj3
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
GHSA-23fp-fmrv-f5px
Uncontrolled Resource Consumption in strapi
GHSA-23fm-wgmf-mc43
Rejected reason: Not used
GHSA-23fm-v895-3qxq
jh_captcha for Typo3 XSS Vulnerability
GHSA-23fj-gx6v-3x6c
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.
GHSA-23fj-6rwp-5rq6
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-23fg-w3cv-jf6w
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-23fx-r767-q5g7 An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database. | CVSS3: 8.1 | 0% Низкий | около 1 года назад | |
GHSA-23fx-gfqr-cvpx Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through dagor_2025_01_15. | 0% Низкий | около 2 месяцев назад | ||
GHSA-23fx-92m6-4f2g pretalx allows path traversal in HTML export | CVSS3: 4.3 | 76% Высокий | почти 3 года назад | |
GHSA-23fw-5352-7h9v Improper access control in Decentralized Identity Services allows an unathenticated attacker to disable Verifiable ID's on another tenant. | CVSS3: 7.5 | 8% Низкий | больше 1 года назад | |
GHSA-23fv-pj9m-qvh4 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-23fv-m8pv-77j9 HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-23fr-29gc-hh5j McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. | 0% Низкий | почти 4 года назад | ||
GHSA-23fq-q7hc-993r HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 | CVSS3: 9.8 | 0% Низкий | больше 4 лет назад | |
GHSA-23fq-fj6g-jf68 IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite. | 12% Средний | почти 4 года назад | ||
GHSA-23fq-26rx-3gc4 Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page. | 0% Низкий | почти 4 года назад | ||
GHSA-23fp-xqj8-q68w SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action. | 0% Низкий | почти 4 года назад | ||
GHSA-23fp-wmqj-rfh4 Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_LT.ASP'. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-23fp-mrfv-cwv4 vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern. | CVSS3: 10 | 69% Средний | 10 месяцев назад | |
GHSA-23fp-mccx-jgj3 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-23fp-fmrv-f5px Uncontrolled Resource Consumption in strapi | CVSS3: 4.9 | 1% Низкий | больше 4 лет назад | |
GHSA-23fm-wgmf-mc43 Rejected reason: Not used | около 1 года назад | |||
GHSA-23fm-v895-3qxq jh_captcha for Typo3 XSS Vulnerability | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-23fj-gx6v-3x6c The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-23fj-6rwp-5rq6 Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | 10 месяцев назад | |
GHSA-23fg-w3cv-jf6w In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp(). | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу