Количество 375 356
Количество 375 356
GHSA-4r3p-r3fh-c2xr
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
GHSA-4r3p-cxgg-r53c
A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
GHSA-4r3m-j6x5-48m3
Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings
GHSA-4r3h-7hr5-pjx6
Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.
GHSA-4r3h-4pgq-8rpc
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
GHSA-4r3g-w96h-5qxg
Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
GHSA-4r3g-w24c-gpr6
Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp
GHSA-4r3g-2r86-vmh6
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
GHSA-4r3f-c7x3-6vc2
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
GHSA-4r3c-w524-c83m
Use after free issue occurs If another instance of open for voice_svc node has been called from application without closing the previous one. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
GHSA-4r3c-9hx8-87cc
A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_avaliacao_desempenho_cad.php. The manipulation of the argument titulo_avaliacao/descricao leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-4r3c-72vr-vf8h
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.
GHSA-4r3c-5hpg-58qr
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
GHSA-4r39-fvrv-xrfj
A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696)
GHSA-4r39-f4rh-j6q8
Missing permission check in Jenkins Gerrit Trigger Plugin
GHSA-4r39-95r5-429h
SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.
GHSA-4r39-5xx8-q235
An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability.
GHSA-4r38-rqh5-3fvr
Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.5.5.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.
GHSA-4r38-38gx-5vr9
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
GHSA-4r38-2fwm-9vj5
In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4r3p-r3fh-c2xr SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database | CVSS3: 7.2 | 1% Низкий | около 1 года назад | |
GHSA-4r3p-cxgg-r53c A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | CVSS3: 7.3 | 0% Низкий | 3 месяца назад | |
GHSA-4r3m-j6x5-48m3 Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings | CVSS3: 7.3 | 1% Низкий | около 6 лет назад | |
GHSA-4r3h-7hr5-pjx6 Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r3h-4pgq-8rpc The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. | CVSS3: 5.3 | 6% Низкий | больше 4 лет назад | |
GHSA-4r3g-w96h-5qxg Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-4r3g-w24c-gpr6 Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp | 1% Низкий | больше 4 лет назад | ||
GHSA-4r3g-2r86-vmh6 b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4r3f-c7x3-6vc2 Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
GHSA-4r3c-w524-c83m Use after free issue occurs If another instance of open for voice_svc node has been called from application without closing the previous one. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24 | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4r3c-9hx8-87cc A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_avaliacao_desempenho_cad.php. The manipulation of the argument titulo_avaliacao/descricao leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.5 | 0% Низкий | около 1 года назад | |
GHSA-4r3c-72vr-vf8h Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file. | 3% Низкий | больше 4 лет назад | ||
GHSA-4r3c-5hpg-58qr Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-4r39-fvrv-xrfj A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696) | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-4r39-f4rh-j6q8 Missing permission check in Jenkins Gerrit Trigger Plugin | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-4r39-95r5-429h SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r39-5xx8-q235 An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability. | CVSS3: 7.8 | 17% Средний | больше 4 лет назад | |
GHSA-4r38-rqh5-3fvr Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.5.5.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility. | CVSS3: 8.8 | 2% Низкий | около 2 лет назад | |
GHSA-4r38-38gx-5vr9 PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r38-2fwm-9vj5 In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. | CVSS3: 5.6 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу