Количество 375 453
Количество 375 453
GHSA-4v4v-wmpc-5vh5
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-4v4v-fcfx-x6mg
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
GHSA-4v4v-cgjf-p5g2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5.
GHSA-4v4v-92cx-x4f4
Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form
GHSA-4v4v-6cx5-x258
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).
GHSA-4v4q-xr4r-hm4m
The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation.
GHSA-4v4q-r2mh-q7w6
Microsoft Defender Remote Code Execution Vulnerability
GHSA-4v4q-53h2-r6mj
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.
GHSA-4v4p-87m3-5423
Known v1.3.1 contains Insecure Direct Object Reference
GHSA-4v4m-xjj9-g6j7
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
GHSA-4v4m-mxm3-w2h7
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with kernel privileges.
GHSA-4v4m-mgj6-c8jv
Windows NT OS Kernel Elevation of Privilege Vulnerability
GHSA-4v4m-hgv5-x3qx
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
GHSA-4v4j-f74g-gxqv
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.
GHSA-4v4j-83q8-87wq
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.
GHSA-4v4h-m2qq-ppgw
Kirby: Request header injection in `Http\Remote`
GHSA-4v4h-6mhp-rwxf
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.
GHSA-4v4h-3w7f-m5wp
There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly.Affected product versions include:Product Name version Affected Version;Anne-AL00 versions Versions earlier than 9.1.0.331(C675E9R1P3T8);Berkeley-L09 versions Versions earlier than 10.0.1.1(C675R1);CD16-10 versions Versions earlier than 10.0.2.8;CD17-10 versions Versions earlier than 10.0.2.8;CD17-16 versions Versions earlier than 10.0.2.8;CD18-10 versions Versions earlier than 10.0.2.8;CD18-16 versions Versions earlier than 10.0.2.8;Columbia-TL00B versions Versions earlier than 9.0.0.187(C01E181R1P20T8);E6878-370 versions Versions earlier than 10.0.5.1(H610SP10C00);Honor 10 Lite versions Versions earlier than 10.0.0.182(C675E17R2P2);LelandP-L22A versions Versions earlier than 9.1.0.166(C675E5R1P4T8);TC5200-16 versions
GHSA-4v4g-vfv9-gvgj
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
GHSA-4v4g-7cw5-m7vc
A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4v4v-wmpc-5vh5 A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.7 | 1% Низкий | больше 1 года назад | |
GHSA-4v4v-fcfx-x6mg CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-4v4v-cgjf-p5g2 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5. | CVSS3: 5.9 | 0% Низкий | около 2 лет назад | |
GHSA-4v4v-92cx-x4f4 Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-4v4v-6cx5-x258 Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS). | 1% Низкий | больше 4 лет назад | ||
GHSA-4v4q-xr4r-hm4m The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-4v4q-r2mh-q7w6 Microsoft Defender Remote Code Execution Vulnerability | CVSS3: 7.8 | 39% Средний | больше 4 лет назад | |
GHSA-4v4q-53h2-r6mj In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy. | 1% Низкий | больше 4 лет назад | ||
GHSA-4v4p-87m3-5423 Known v1.3.1 contains Insecure Direct Object Reference | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-4v4m-xjj9-g6j7 SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-4v4m-mxm3-w2h7 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with kernel privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-4v4m-mgj6-c8jv Windows NT OS Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 4% Низкий | почти 2 года назад | |
GHSA-4v4m-hgv5-x3qx A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4v4j-f74g-gxqv Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905. | 6% Низкий | больше 4 лет назад | ||
GHSA-4v4j-83q8-87wq Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05. | 3% Низкий | больше 4 лет назад | ||
GHSA-4v4h-m2qq-ppgw Kirby: Request header injection in `Http\Remote` | 0% Низкий | 3 месяца назад | ||
GHSA-4v4h-6mhp-rwxf The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to. | CVSS3: 2.7 | 0% Низкий | около 2 месяцев назад | |
GHSA-4v4h-3w7f-m5wp There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly.Affected product versions include:Product Name version Affected Version;Anne-AL00 versions Versions earlier than 9.1.0.331(C675E9R1P3T8);Berkeley-L09 versions Versions earlier than 10.0.1.1(C675R1);CD16-10 versions Versions earlier than 10.0.2.8;CD17-10 versions Versions earlier than 10.0.2.8;CD17-16 versions Versions earlier than 10.0.2.8;CD18-10 versions Versions earlier than 10.0.2.8;CD18-16 versions Versions earlier than 10.0.2.8;Columbia-TL00B versions Versions earlier than 9.0.0.187(C01E181R1P20T8);E6878-370 versions Versions earlier than 10.0.5.1(H610SP10C00);Honor 10 Lite versions Versions earlier than 10.0.0.182(C675E17R2P2);LelandP-L22A versions Versions earlier than 9.1.0.166(C675E5R1P4T8);TC5200-16 versions | 0% Низкий | больше 4 лет назад | ||
GHSA-4v4g-vfv9-gvgj Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. | CVSS3: 7.5 | 1% Низкий | 11 месяцев назад | |
GHSA-4v4g-7cw5-m7vc A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу