Количество 371 326
Количество 371 326
GHSA-4g4c-8gqh-m4vm
paranoid2 gem Code backdoor
GHSA-4g4c-285h-w45p
A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. The manipulation of the argument ef_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272579.
GHSA-4g49-qqgp-g5cv
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
GHSA-4g49-fgg9-9m4w
Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."
GHSA-4g48-xcj2-xjr4
Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.
GHSA-4g48-m7qw-9j6j
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
GHSA-4g48-c9r3-fjv8
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.
GHSA-4g48-54q2-fg7q
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
GHSA-4g48-423m-8v44
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. NOTE: The patch for this vulnerability is reported to be incomplete: /etc/shadow was remediated but /etc/sudoers remains vulnerable.
GHSA-4g47-3fx3-5q52
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
GHSA-4g46-5grc-wq49
Cross-Site Scripting in seeftl
GHSA-4g45-vj69-x97c
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).
GHSA-4g45-rw93-8jmc
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.
GHSA-4g44-xjmc-rxcq
Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.
GHSA-4g44-cv7p-fgrg
In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.
GHSA-4g44-5j4j-c7x6
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
GHSA-4g44-2wm9-33xf
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
GHSA-4g43-pmw7-v27w
In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().
GHSA-4g43-jcgp-9p5g
Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.
GHSA-4g42-x277-3hhc
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4g4c-8gqh-m4vm paranoid2 gem Code backdoor | CVSS3: 9.8 | 4% Низкий | около 7 лет назад | |
GHSA-4g4c-285h-w45p A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. The manipulation of the argument ef_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272579. | CVSS3: 6.3 | 1% Низкий | около 2 лет назад | |
GHSA-4g49-qqgp-g5cv A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g49-fgg9-9m4w Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes." | 1% Низкий | больше 4 лет назад | ||
GHSA-4g48-xcj2-xjr4 Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g48-m7qw-9j6j Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4g48-c9r3-fjv8 Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-4g48-54q2-fg7q Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access | CVSS3: 6.5 | 1% Низкий | 5 месяцев назад | |
GHSA-4g48-423m-8v44 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. NOTE: The patch for this vulnerability is reported to be incomplete: /etc/shadow was remediated but /etc/sudoers remains vulnerable. | CVSS3: 7.8 | 0% Низкий | 12 месяцев назад | |
GHSA-4g47-3fx3-5q52 In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration. | 3% Низкий | больше 4 лет назад | ||
GHSA-4g46-5grc-wq49 Cross-Site Scripting in seeftl | 1% Низкий | больше 6 лет назад | ||
GHSA-4g45-vj69-x97c An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020). | 0% Низкий | больше 4 лет назад | ||
GHSA-4g45-rw93-8jmc An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4g44-xjmc-rxcq Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4g44-cv7p-fgrg In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-4g44-5j4j-c7x6 In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability. | CVSS3: 9.8 | 7% Низкий | больше 4 лет назад | |
GHSA-4g44-2wm9-33xf The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4g43-pmw7-v27w In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2(). | CVSS3: 8.1 | 0% Низкий | 10 месяцев назад | |
GHSA-4g43-jcgp-9p5g Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g42-x277-3hhc A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу