Количество 322 267
Количество 322 267
GHSA-223p-pjp4-9vv5
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.
GHSA-223p-m2w6-92v2
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
GHSA-223p-3v7f-rwxh
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to access sensitive user data.
GHSA-223m-pgcq-f3xg
Jenkins Fortify Plugin HTML injection vulnerability
GHSA-223m-mhgp-x54c
Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe payloads in the text parameter to store malicious content that executes in the browsers of users viewing the affected pages.
GHSA-223m-fhfm-47hr
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.
GHSA-223m-4rfp-646h
Jenkins is missing a permission check in the authenticated users' profile menu
GHSA-223j-w649-gh98
Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2.
GHSA-223j-8f9f-qhc5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.
GHSA-223j-7cj4-4cw7
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
GHSA-223j-4rm8-mrmf
Next.js may leak x-middleware-subrequest-id to external hosts
GHSA-223h-r336-f673
Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system.
GHSA-223g-8w3x-98wr
Snowflake Connector .Net Command Injection
GHSA-223f-f395-r8rw
A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
GHSA-223c-vgc5-mrv4
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.
GHSA-223c-8f3h-q9f9
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
GHSA-2239-q247-vvp8
Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2239-pmp7-cm44
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262226 is the identifier assigned to this vulnerability.
GHSA-2239-h2rh-5fp9
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.
GHSA-2238-xc5r-v9hj
@tinacms/graphql has a Path Traversal issue
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-223p-pjp4-9vv5 An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-223p-m2w6-92v2 IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment. | CVSS3: 4.9 | 0% Низкий | 12 месяцев назад | |
GHSA-223p-3v7f-rwxh This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to access sensitive user data. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-223m-pgcq-f3xg Jenkins Fortify Plugin HTML injection vulnerability | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-223m-mhgp-x54c Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe payloads in the text parameter to store malicious content that executes in the browsers of users viewing the affected pages. | CVSS3: 6.4 | 0% Низкий | 9 дней назад | |
GHSA-223m-fhfm-47hr PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php. | 4% Низкий | почти 4 года назад | ||
GHSA-223m-4rfp-646h Jenkins is missing a permission check in the authenticated users' profile menu | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
GHSA-223j-w649-gh98 Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2. | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
GHSA-223j-8f9f-qhc5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-223j-7cj4-4cw7 Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0. | CVSS3: 9.1 | 0% Низкий | около 1 года назад | |
GHSA-223j-4rm8-mrmf Next.js may leak x-middleware-subrequest-id to external hosts | 0% Низкий | 12 месяцев назад | ||
GHSA-223h-r336-f673 Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system. | CVSS3: 7.8 | 11% Средний | почти 3 года назад | |
GHSA-223g-8w3x-98wr Snowflake Connector .Net Command Injection | CVSS3: 7.3 | 3% Низкий | почти 3 года назад | |
GHSA-223f-f395-r8rw A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | CVSS3: 7.3 | 0% Низкий | 3 месяца назад | |
GHSA-223c-vgc5-mrv4 Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action. | 0% Низкий | почти 4 года назад | ||
GHSA-223c-8f3h-q9f9 A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-2239-q247-vvp8 Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 3% Низкий | почти 4 года назад | ||
GHSA-2239-pmp7-cm44 A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262226 is the identifier assigned to this vulnerability. | CVSS3: 6.3 | 0% Низкий | почти 2 года назад | |
GHSA-2239-h2rh-5fp9 Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-2238-xc5r-v9hj @tinacms/graphql has a Path Traversal issue | CVSS3: 6.3 | 0% Низкий | 13 дней назад |
Уязвимостей на страницу