Количество 371 326
Количество 371 326
GHSA-4gfg-qwj4-89qg
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.
GHSA-4gfg-32rq-7753
SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter.
GHSA-4gff-x4ff-9qq7
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request. The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.
GHSA-4gff-g5qg-73wc
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
GHSA-4gff-fjgq-76g6
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
GHSA-4gfc-72gw-v385
Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability
GHSA-4gf9-gwj2-w3rx
An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.
GHSA-4gf9-6xwj-3w66
Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.
GHSA-4gf8-cwcf-3hph
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Motacek ICS Button allows Stored XSS.This issue affects ICS Button: from n/a through 0.6.
GHSA-4gf7-m762-7xq9
IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
GHSA-4gf7-ff8x-hq99
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
GHSA-4gf7-cp73-grc5
Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.
GHSA-4gf7-49hm-67v5
Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters.
GHSA-4gf6-p85h-2wcf
A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
GHSA-4gf4-qjr3-ppxj
Windows Geolocation Service Remote Code Execution Vulnerability.
GHSA-4gf4-mg8f-6224
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
GHSA-4gf4-5fpq-6cwc
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.
GHSA-4gf4-55f6-hq4x
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.
GHSA-4gf2-xv97-63m2
Exposure of Sensitive Information in keycloak
GHSA-4gf2-6j5v-x6gv
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4gfg-qwj4-89qg SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action. | 1% Низкий | больше 4 лет назад | ||
GHSA-4gfg-32rq-7753 SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-4gff-x4ff-9qq7 Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request. The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch. | CVSS3: 4.7 | 0% Низкий | почти 2 года назад | |
GHSA-4gff-g5qg-73wc Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). | CVSS3: 6.6 | 0% Низкий | около 2 месяцев назад | |
GHSA-4gff-fjgq-76g6 User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-4gfc-72gw-v385 Jenkins Nexus Platform Plugin Cross-Site Request Forgery vulnerability | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-4gf9-gwj2-w3rx An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4gf9-6xwj-3w66 Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times. | 1% Низкий | больше 4 лет назад | ||
GHSA-4gf8-cwcf-3hph Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Motacek ICS Button allows Stored XSS.This issue affects ICS Button: from n/a through 0.6. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-4gf7-m762-7xq9 IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072. | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
GHSA-4gf7-ff8x-hq99 Opening a malicious website while running a Nuxt dev server could allow read-only access to code | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-4gf7-cp73-grc5 Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter. | CVSS3: 7.4 | 2% Низкий | больше 4 лет назад | |
GHSA-4gf7-49hm-67v5 Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) start or (2) sort parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-4gf6-p85h-2wcf A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. | CVSS3: 8.8 | 3% Низкий | 9 месяцев назад | |
GHSA-4gf4-qjr3-ppxj Windows Geolocation Service Remote Code Execution Vulnerability. | CVSS3: 7.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4gf4-mg8f-6224 D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022. | CVSS3: 9.8 | 65% Средний | почти 4 года назад | |
GHSA-4gf4-5fpq-6cwc PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4gf4-55f6-hq4x SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824. | 2% Низкий | больше 4 лет назад | ||
GHSA-4gf2-xv97-63m2 Exposure of Sensitive Information in keycloak | CVSS3: 5.6 | 1% Низкий | почти 5 лет назад | |
GHSA-4gf2-6j5v-x6gv Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. | 80% Высокий | больше 4 лет назад |
Уязвимостей на страницу