Количество 375 453
Количество 375 453
GHSA-4v3m-mrm4-6g89
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
GHSA-4v3m-fhx4-qp25
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
GHSA-4v3j-q36m-pfpg
Windows Kerberos Elevation of Privilege Vulnerability.
GHSA-4v3j-f48c-mxfv
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
GHSA-4v3j-7fcp-c89c
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.
GHSA-4v3j-3fr4-cjrj
In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix memory leak in wbrf_record() The tmp buffer is allocated using kcalloc() but is not freed if acpi_evaluate_dsm() fails. This causes a memory leak in the error path. Fix this by explicitly freeing the tmp buffer in the error handling path of acpi_evaluate_dsm().
GHSA-4v3g-g84w-hv7r
Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
GHSA-4v3g-f433-532p
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA-4v3g-89jr-8hcp
A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.
GHSA-4v3f-x74x-h275
A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.8 is able to address this issue. The name of the patch is 7d5b9a89a27711aad76fd55ab4cc4185b545a1d0. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221479.
GHSA-4v3f-mvph-6j7c
Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_DLG.ASP'.
GHSA-4v3f-ffrw-xcx6
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.
GHSA-4v3f-8w78-rm7j
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.9.
GHSA-4v3f-4r92-c6v3
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
GHSA-4v3c-22g9-x3jm
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
GHSA-4v39-rw5r-p8jm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder allows Stored XSS. This issue affects Team Members for Elementor Page Builder: from n/a through 1.0.4.
GHSA-4v39-q2jh-wjrw
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
GHSA-4v39-fjgh-5mwf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Scroll Top allows Reflected XSS. This issue affects Scroll Top: from n/a through 1.3.3.
GHSA-4v39-87g3-6x6j
Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.
GHSA-4v38-w5qx-qhmh
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4v3m-mrm4-6g89 SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component. | CVSS3: 7.2 | 1% Низкий | больше 1 года назад | |
GHSA-4v3m-fhx4-qp25 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4v3j-q36m-pfpg Windows Kerberos Elevation of Privilege Vulnerability. | CVSS3: 8.8 | 5% Низкий | больше 4 лет назад | |
GHSA-4v3j-f48c-mxfv Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-4v3j-7fcp-c89c The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries. | CVSS3: 8.2 | 1% Низкий | больше 4 лет назад | |
GHSA-4v3j-3fr4-cjrj In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: Fix memory leak in wbrf_record() The tmp buffer is allocated using kcalloc() but is not freed if acpi_evaluate_dsm() fails. This causes a memory leak in the error path. Fix this by explicitly freeing the tmp buffer in the error handling path of acpi_evaluate_dsm(). | CVSS3: 5.5 | 0% Низкий | 8 месяцев назад | |
GHSA-4v3g-g84w-hv7r Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat | CVSS3: 9.1 | 10% Средний | больше 4 лет назад | |
GHSA-4v3g-f433-532p Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 6% Низкий | больше 4 лет назад | ||
GHSA-4v3g-89jr-8hcp A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities. | CVSS3: 8.4 | 1% Низкий | больше 2 лет назад | |
GHSA-4v3f-x74x-h275 A vulnerability was found in madgicweb BuddyStream Plugin up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file ShareBox.php. The manipulation of the argument content/link/shares leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.8 is able to address this issue. The name of the patch is 7d5b9a89a27711aad76fd55ab4cc4185b545a1d0. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221479. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-4v3f-mvph-6j7c Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_DLG.ASP'. | CVSS3: 6.1 | 0% Низкий | 12 месяцев назад | |
GHSA-4v3f-ffrw-xcx6 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data. | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
GHSA-4v3f-8w78-rm7j Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.9. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4v3f-4r92-c6v3 A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 77% Высокий | больше 1 года назад | |
GHSA-4v3c-22g9-x3jm IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4v39-rw5r-p8jm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder allows Stored XSS. This issue affects Team Members for Elementor Page Builder: from n/a through 1.0.4. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-4v39-q2jh-wjrw Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request. | CVSS3: 9.8 | 94% Критический | около 3 лет назад | |
GHSA-4v39-fjgh-5mwf Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Scroll Top allows Reflected XSS. This issue affects Scroll Top: from n/a through 1.3.3. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-4v39-87g3-6x6j Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document. | 3% Низкий | больше 4 лет назад | ||
GHSA-4v38-w5qx-qhmh In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow. | CVSS3: 9.8 | 7% Низкий | больше 4 лет назад |
Уязвимостей на страницу