Количество 375 356
Количество 375 356
GHSA-4rhq-vpg8-62j3
In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-4rhq-r59j-x4fc
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chrome security severity: Medium)
GHSA-4rhp-v69r-6w59
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
GHSA-4rhm-m2fp-hx7q
Potential CSV Injection vector in OctoberCMS
GHSA-4rhm-7j67-99mp
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.
GHSA-4rhh-qhhp-cw22
NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.
GHSA-4rhg-qwrc-fj7f
Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
GHSA-4rhg-p5c5-29q7
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
GHSA-4rhg-h8f2-v4jm
pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
GHSA-4rhg-f685-m3px
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
GHSA-4rhg-84mj-rx7h
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
GHSA-4rhg-7crh-vmfw
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).
GHSA-4rhf-x5cr-x2mw
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf03514.
GHSA-4rhf-g669-h99f
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
GHSA-4rhf-85wr-9pxc
A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
GHSA-4rhc-q92g-rm98
A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-4rhc-pqwm-9j5g
Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.
GHSA-4rhc-g7g9-q5w5
hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
GHSA-4rhc-2pqf-hqj3
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
GHSA-4rh8-xrf7-26m9
Rejected reason: Not used
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4rhq-vpg8-62j3 In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-4rhq-r59j-x4fc Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chrome security severity: Medium) | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-4rhp-v69r-6w59 In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE). | CVSS3: 8.8 | 23% Средний | почти 4 года назад | |
GHSA-4rhm-m2fp-hx7q Potential CSV Injection vector in OctoberCMS | CVSS3: 4 | 1% Низкий | больше 6 лет назад | |
GHSA-4rhm-7j67-99mp Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-4rhh-qhhp-cw22 NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application. | CVSS3: 8.2 | 0% Низкий | 9 месяцев назад | |
GHSA-4rhg-qwrc-fj7f Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-4rhg-p5c5-29q7 SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. | CVSS3: 9.8 | 7% Низкий | больше 4 лет назад | |
GHSA-4rhg-h8f2-v4jm pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
GHSA-4rhg-f685-m3px Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4rhg-84mj-rx7h admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4rhg-7crh-vmfw An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020). | 0% Низкий | больше 4 лет назад | ||
GHSA-4rhf-x5cr-x2mw A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf03514. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4rhf-g669-h99f Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). | CVSS3: 9.3 | 0% Низкий | 3 месяца назад | |
GHSA-4rhf-85wr-9pxc A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-4rhc-q92g-rm98 A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-4rhc-pqwm-9j5g Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-4rhc-g7g9-q5w5 hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | CVSS3: 8 | 1% Низкий | больше 4 лет назад | |
GHSA-4rhc-2pqf-hqj3 A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-4rh8-xrf7-26m9 Rejected reason: Not used | 11 месяцев назад |
Уязвимостей на страницу