Количество 375 453
Количество 375 453
GHSA-4v38-rxj3-wf34
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.
GHSA-4v38-964c-xjmw
Code injection via unescaped translations in xwiki-platform
GHSA-4v38-4r78-53pv
Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
GHSA-4v37-24gm-h554
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4
GHSA-4v36-9pjv-6h63
The New Beginnings CFC (aka com.goodbarber.nbcfc) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4v36-7w47-pxwg
In the Linux kernel, the following vulnerability has been resolved: ip: Fix data-races around sysctl_ip_fwd_update_priority. While reading sysctl_ip_fwd_update_priority, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.
GHSA-4v36-769x-7cpq
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
GHSA-4v35-rh24-xvq6
The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
GHSA-4v35-78jc-648r
Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-4v35-68f6-rfpq
An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later
GHSA-4v34-q2vw-9m7j
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.
GHSA-4v34-gm3m-8x92
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).
GHSA-4v34-9x49-p452
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
GHSA-4v32-vrp2-28jp
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
GHSA-4v32-6xw7-c96f
The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenticated attacker can use that parameter to execute arbitrary OS commands.
GHSA-4v2x-jqm6-7wqw
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.
GHSA-4v2w-h9jm-mqjg
Prototype Pollution in systeminformation
GHSA-4v2w-2wqp-mc85
OpenAM OAuth Authorization Bypass via PKCE Challenge
GHSA-4v2v-p6m7-q4jj
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
GHSA-4v2v-7w44-wqvx
IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4v38-rxj3-wf34 SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074. | 1% Низкий | больше 4 лет назад | ||
GHSA-4v38-964c-xjmw Code injection via unescaped translations in xwiki-platform | CVSS3: 9.9 | 2% Низкий | больше 3 лет назад | |
GHSA-4v38-4r78-53pv Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status. | 12% Средний | больше 4 лет назад | ||
GHSA-4v37-24gm-h554 Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4 | CVSS3: 6.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4v36-9pjv-6h63 The New Beginnings CFC (aka com.goodbarber.nbcfc) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4v36-7w47-pxwg In the Linux kernel, the following vulnerability has been resolved: ip: Fix data-races around sysctl_ip_fwd_update_priority. While reading sysctl_ip_fwd_update_priority, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers. | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-4v36-769x-7cpq cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4v35-rh24-xvq6 The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4v35-78jc-648r Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows | 2 месяца назад | |||
GHSA-4v35-68f6-rfpq An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later | CVSS3: 6.3 | 1% Низкий | больше 2 лет назад | |
GHSA-4v34-q2vw-9m7j Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4v34-gm3m-8x92 groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter). | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4v34-9x49-p452 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | CVSS3: 7.8 | 28% Средний | около 3 лет назад | |
GHSA-4v32-vrp2-28jp Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
GHSA-4v32-6xw7-c96f The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenticated attacker can use that parameter to execute arbitrary OS commands. | CVSS3: 6.5 | 6% Низкий | около 1 года назад | |
GHSA-4v2x-jqm6-7wqw A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences. | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
GHSA-4v2w-h9jm-mqjg Prototype Pollution in systeminformation | CVSS3: 8.1 | 2% Низкий | почти 6 лет назад | |
GHSA-4v2w-2wqp-mc85 OpenAM OAuth Authorization Bypass via PKCE Challenge | 0% Низкий | 3 месяца назад | ||
GHSA-4v2v-p6m7-q4jj MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4v2v-7w44-wqvx IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу