Количество 373 528
Количество 373 528
GHSA-4jh8-xj74-jhxx
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options
GHSA-4jh8-f2cr-j6hg
Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.
GHSA-4jh8-5fmv-rj32
Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-4jh7-wh4m-f4pq
Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file.
GHSA-4jh7-m9q3-3qw9
CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.
GHSA-4jh7-c2vv-7qf2
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.
GHSA-4jh7-7xmh-98px
A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.
GHSA-4jh6-hfr3-fg82
The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
GHSA-4jh6-gx4g-g6m8
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
GHSA-4jh6-gh8q-jcwr
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.
GHSA-4jh6-6j22-8j58
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
GHSA-4jh5-ggm8-wxch
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
GHSA-4jh5-9c29-9299
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.
GHSA-4jh5-95f7-hf6w
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-4jh4-xcv6-j74j
Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
GHSA-4jh4-mwq8-wx24
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
GHSA-4jh4-4vjf-72wq
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29.
GHSA-4jh3-6jhv-2mgp
react-native-mmkv Insertion of Sensitive Information into Log File vulnerability
GHSA-4jh3-696v-qm6r
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
GHSA-4jh2-4rxm-r2jw
SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4jh8-xj74-jhxx An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options | CVSS3: 9.1 | 0% Низкий | 7 месяцев назад | |
GHSA-4jh8-f2cr-j6hg Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-4jh8-5fmv-rj32 Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-4jh7-wh4m-f4pq Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file. | 64% Средний | больше 4 лет назад | ||
GHSA-4jh7-m9q3-3qw9 CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. | CVSS3: 6.1 | 1% Низкий | около 2 лет назад | |
GHSA-4jh7-c2vv-7qf2 Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-4jh7-7xmh-98px A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17. | 1% Низкий | больше 4 лет назад | ||
GHSA-4jh6-hfr3-fg82 The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software. | 3% Низкий | больше 4 лет назад | ||
GHSA-4jh6-gx4g-g6m8 An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine. | CVSS3: 9 | 1% Низкий | 11 месяцев назад | |
GHSA-4jh6-gh8q-jcwr Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | 5% Низкий | больше 4 лет назад | ||
GHSA-4jh6-6j22-8j58 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | CVSS3: 5.6 | 0% Низкий | около 1 года назад | |
GHSA-4jh5-ggm8-wxch Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 1% Низкий | больше 4 лет назад | ||
GHSA-4jh5-9c29-9299 Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action. | 1% Низкий | больше 4 лет назад | ||
GHSA-4jh5-95f7-hf6w A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 5.3 | 13% Средний | больше 1 года назад | |
GHSA-4jh4-xcv6-j74j Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | 0% Низкий | больше 4 лет назад | ||
GHSA-4jh4-mwq8-wx24 The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions. | CVSS3: 7.4 | 0% Низкий | почти 3 года назад | |
GHSA-4jh4-4vjf-72wq libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4jh3-6jhv-2mgp react-native-mmkv Insertion of Sensitive Information into Log File vulnerability | CVSS3: 4.4 | 0% Низкий | больше 2 лет назад | |
GHSA-4jh3-696v-qm6r sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. | CVSS3: 5.3 | 3% Низкий | больше 4 лет назад | |
GHSA-4jh2-4rxm-r2jw SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу