Количество 370 914
Количество 370 914
GHSA-4c8p-2m43-22fp
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.
GHSA-4c8m-878j-r5j4
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.
GHSA-4c8m-6fwx-m7xq
Concrete CMS contains a CSRF vulnerability
GHSA-4c8j-w686-c2jw
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
GHSA-4c8j-pqvg-527j
PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."
GHSA-4c8j-mgm4-qqvp
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
GHSA-4c8j-5c7v-3fw3
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction.
GHSA-4c8j-3p6w-vq76
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /register.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-4c8h-qwf9-6p7g
The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.
GHSA-4c8h-hw7r-25rm
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
GHSA-4c8h-h3m6-vv44
The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183.
GHSA-4c8h-4mm2-mm5g
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
GHSA-4c8g-jvcx-v4hv
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
GHSA-4c8g-9w4h-h6xm
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
GHSA-4c8g-83qw-93j6
fast-uri vulnerable to host confusion via failed IDN canonicalization
GHSA-4c8f-vrv5-3jh4
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.
GHSA-4c8f-q362-56jq
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
GHSA-4c8f-3m6h-m56r
Gitea primary email ownership bypass allows cross-user email changes
GHSA-4c89-qj95-32wv
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
GHSA-4c89-m7v4-f4xx
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4c8p-2m43-22fp The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-4c8m-878j-r5j4 Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-4c8m-6fwx-m7xq Concrete CMS contains a CSRF vulnerability | 0% Низкий | 4 месяца назад | ||
GHSA-4c8j-w686-c2jw The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function. | 1% Низкий | больше 4 лет назад | ||
GHSA-4c8j-pqvg-527j PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability." | 2% Низкий | больше 4 лет назад | ||
GHSA-4c8j-mgm4-qqvp Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
GHSA-4c8j-5c7v-3fw3 WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user interaction. | CVSS3: 9.8 | 6% Низкий | 8 месяцев назад | |
GHSA-4c8j-3p6w-vq76 A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /register.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | около 1 года назад | |
GHSA-4c8h-qwf9-6p7g The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request. | 2% Низкий | больше 4 лет назад | ||
GHSA-4c8h-hw7r-25rm Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-4c8h-h3m6-vv44 The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183. | 3% Низкий | больше 4 лет назад | ||
GHSA-4c8h-4mm2-mm5g Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation. | CVSS3: 4.4 | 38% Средний | почти 2 года назад | |
GHSA-4c8g-jvcx-v4hv Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access | CVSS3: 5.2 | 0% Низкий | 3 месяца назад | |
GHSA-4c8g-9w4h-h6xm If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalization | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-4c8f-vrv5-3jh4 Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor. | CVSS3: 8.8 | 4% Низкий | больше 4 лет назад | |
GHSA-4c8f-q362-56jq In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | CVSS3: 3.5 | 1% Низкий | почти 2 года назад | |
GHSA-4c8f-3m6h-m56r Gitea primary email ownership bypass allows cross-user email changes | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-4c89-qj95-32wv Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-4c89-m7v4-f4xx PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу