Количество 375 356
Количество 375 356
GHSA-4r8x-26vf-3hx6
The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.
GHSA-4r8w-vcjg-cxx6
Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279.
GHSA-4r8w-crc8-mqph
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.
GHSA-4r8w-73jc-3m7q
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
GHSA-4r8w-3jww-m2rp
Strapi is vulnerable to Insufficient Session Expiration
GHSA-4r8v-w9wf-3vgm
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
GHSA-4r8v-rcc7-72xr
In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-4r8v-7f5q-9mr7
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
GHSA-4r8r-m45w-c7cj
A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
GHSA-4r8r-cjr4-hvqr
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
GHSA-4r8r-5r92-x2m5
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of MedDream WEB DICOM Viewer. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Web Portal. The issue results from the lack of encryption when transmitting credentials. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-25842.
GHSA-4r8r-4jfr-7g35
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal).
GHSA-4r8q-m228-4jmx
The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related to the $info{'forum'} variable.
GHSA-4r8q-j6h7-r23w
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.
GHSA-4r8q-gv9j-3xx6
Open Redirect
GHSA-4r8q-2frh-4j22
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
GHSA-4r8p-gh25-7c48
A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-4r8p-6r2m-cjwv
A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its components value. Therefore, the loop code assumes that exp->NumberOfFunctions is greater than ordinal at each iteration. This can lead to arbitrary code execution.
GHSA-4r8m-xw24-v2mc
Vulnerability in IntraGnat before 1.4.
GHSA-4r8m-m7vp-cj97
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4r8x-26vf-3hx6 The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled. | CVSS3: 4.8 | 0% Низкий | около 2 лет назад | |
GHSA-4r8w-vcjg-cxx6 Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r8w-crc8-mqph Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11. | CVSS3: 9.8 | 0% Низкий | 7 месяцев назад | |
GHSA-4r8w-73jc-3m7q Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-4r8w-3jww-m2rp Strapi is vulnerable to Insufficient Session Expiration | 1% Низкий | 11 месяцев назад | ||
GHSA-4r8v-w9wf-3vgm Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
GHSA-4r8v-rcc7-72xr In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.8 | 0% Низкий | 12 дней назад | |
GHSA-4r8v-7f5q-9mr7 Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level. | CVSS3: 8.5 | 0% Низкий | 5 дней назад | |
GHSA-4r8r-m45w-c7cj A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 6.3 | 4% Низкий | 7 месяцев назад | |
GHSA-4r8r-cjr4-hvqr Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
GHSA-4r8r-5r92-x2m5 MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of MedDream WEB DICOM Viewer. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Web Portal. The issue results from the lack of encryption when transmitting credentials. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-25842. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-4r8r-4jfr-7g35 An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An unauthenticated attacker may be able to access configuration files with a specially crafted URL (Path Traversal). | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-4r8q-m228-4jmx The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related to the $info{'forum'} variable. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r8q-j6h7-r23w Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed. | CVSS3: 2.9 | 0% Низкий | 7 дней назад | |
GHSA-4r8q-gv9j-3xx6 Open Redirect | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4r8q-2frh-4j22 AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4r8p-gh25-7c48 A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.7 | 1% Низкий | больше 1 года назад | |
GHSA-4r8p-6r2m-cjwv A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its components value. Therefore, the loop code assumes that exp->NumberOfFunctions is greater than ordinal at each iteration. This can lead to arbitrary code execution. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4r8m-xw24-v2mc Vulnerability in IntraGnat before 1.4. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r8m-m7vp-cj97 WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу