Количество 375 268
Количество 375 268
GHSA-4qj2-mfrv-5fm4
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0.
GHSA-4qhx-qrcw-q3px
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.
GHSA-4qhx-h7mh-942g
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
GHSA-4qhx-g9wp-g9m6
Failure to sanitize quotes which can lead to sql injection in squel
GHSA-4qhx-g5hg-wvgv
The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file.
GHSA-4qhv-qjg6-r699
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
GHSA-4qhr-qf46-fcrx
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-4qhr-q7wf-94xp
Deserialization of Untrusted Data in JYaml
GHSA-4qhr-g3c6-fcfx
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
GHSA-4qhr-cpgg-2jgg
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.
GHSA-4qhq-qj7h-c7fx
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents.
GHSA-4qhq-9cgj-pg5j
An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.
GHSA-4qhp-mwrw-89jx
Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
GHSA-4qhp-652w-c22x
Unsecured endpoints in the jupyter-lsp server extension
GHSA-4qhm-v7jj-gh6g
Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.
GHSA-4qhm-cjfg-jjv8
IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.
GHSA-4qhm-36g2-5mv9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.
GHSA-4qhj-jmx7-8mr8
Directory Traversal vulnerability in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted file upload
GHSA-4qhh-vhvg-gc9c
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
GHSA-4qhh-phr7-cw2h
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4qj2-mfrv-5fm4 Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0. | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-4qhx-qrcw-q3px SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-4qhx-h7mh-942g Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083. | CVSS3: 8.8 | 4% Низкий | больше 4 лет назад | |
GHSA-4qhx-g9wp-g9m6 Failure to sanitize quotes which can lead to sql injection in squel | больше 7 лет назад | |||
GHSA-4qhx-g5hg-wvgv The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4qhv-qjg6-r699 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 5% Низкий | 4 месяца назад | |
GHSA-4qhr-qf46-fcrx Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability | CVSS3: 8.8 | 11 дней назад | ||
GHSA-4qhr-q7wf-94xp Deserialization of Untrusted Data in JYaml | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-4qhr-g3c6-fcfx Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling | 0% Низкий | около 2 месяцев назад | ||
GHSA-4qhr-cpgg-2jgg A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. | CVSS3: 4.7 | 1% Низкий | больше 1 года назад | |
GHSA-4qhq-qj7h-c7fx Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents. | CVSS3: 8.2 | 0% Низкий | 6 месяцев назад | |
GHSA-4qhq-9cgj-pg5j An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-4qhp-mwrw-89jx Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
GHSA-4qhp-652w-c22x Unsecured endpoints in the jupyter-lsp server extension | CVSS3: 7.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4qhm-v7jj-gh6g Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs. | 4% Низкий | больше 4 лет назад | ||
GHSA-4qhm-cjfg-jjv8 IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
GHSA-4qhm-36g2-5mv9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4qhj-jmx7-8mr8 Directory Traversal vulnerability in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted file upload | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-4qhh-vhvg-gc9c In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | CVSS3: 5.5 | 0% Низкий | около 1 месяца назад | |
GHSA-4qhh-phr7-cw2h An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу