Количество 341 844
Количество 341 844
GHSA-32fm-h45j-grpv
Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.
GHSA-32fm-h2hh-vxjg
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally.
GHSA-32fj-r8qw-r8w8
MindsDB Cross-site Scripting vulnerability
GHSA-32fh-gwcr-7pmx
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.
GHSA-32fg-mvv7-ppfg
Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions.
GHSA-32fg-cv9g-c28f
I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.
GHSA-32fg-c88m-mcrv
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems.
GHSA-32ff-4g79-vgfc
Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings
GHSA-32f9-rqvx-v6wh
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
GHSA-32f8-xfvp-9m45
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded.
GHSA-32f8-hmr3-7vxg
Azure Storage Movement Client Library Denial of Service Vulnerability
GHSA-32f7-x79r-fq9w
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
GHSA-32f7-fg59-hr8r
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/completed-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-32f7-cmr3-vpjv
Moderate severity vulnerability that affects aioxmpp
GHSA-32f6-jrx4-x77h
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment.
GHSA-32f3-8mjf-7qcp
Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table names and sensitive information from the database.
GHSA-32f3-6f6j-9xc3
Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message.
GHSA-32f2-v4v8-76vw
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.
GHSA-32f2-r7gj-x2hp
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.
GHSA-32f2-chgf-rf94
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-32fm-h45j-grpv Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector. | CVSS3: 7.5 | 0% Низкий | 9 месяцев назад | |
GHSA-32fm-h2hh-vxjg Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthorized users may view or execute programs illegally. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-32fj-r8qw-r8w8 MindsDB Cross-site Scripting vulnerability | CVSS3: 9 | 0% Низкий | около 2 лет назад | |
GHSA-32fh-gwcr-7pmx A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-32fg-mvv7-ppfg Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-32fg-cv9g-c28f I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-32fg-c88m-mcrv Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems. | CVSS3: 9.1 | 1% Низкий | 7 месяцев назад | |
GHSA-32ff-4g79-vgfc Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings | CVSS3: 2.7 | 1% Низкий | около 4 лет назад | |
GHSA-32f9-rqvx-v6wh Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-32f8-xfvp-9m45 A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-32f8-hmr3-7vxg Azure Storage Movement Client Library Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | |
GHSA-32f7-x79r-fq9w The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-32f7-fg59-hr8r A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/completed-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-32f7-cmr3-vpjv Moderate severity vulnerability that affects aioxmpp | больше 7 лет назад | |||
GHSA-32f6-jrx4-x77h Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment. | CVSS3: 7.8 | 0% Низкий | 11 месяцев назад | |
GHSA-32f3-8mjf-7qcp Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table names and sensitive information from the database. | CVSS3: 8.2 | 0% Низкий | 6 месяцев назад | |
GHSA-32f3-6f6j-9xc3 Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message. | 3% Низкий | больше 4 лет назад | ||
GHSA-32f2-v4v8-76vw An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using. | 1% Низкий | больше 4 лет назад | ||
GHSA-32f2-r7gj-x2hp Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking. | 1% Низкий | больше 4 лет назад | ||
GHSA-32f2-chgf-rf94 Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host. | CVSS3: 10 | 5% Низкий | больше 4 лет назад |
Уязвимостей на страницу