Количество 370 841
Количество 370 841
GHSA-4c34-f6qc-56qv
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
GHSA-4c33-jjxv-7pfw
Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.
GHSA-4c33-h9j5-vmhj
A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affected is an unknown function of the file /dcwr_entry.php. The manipulation of the argument Date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-4c33-fwgf-qv6r
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
GHSA-4c33-2p78-4q5m
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local File Inclusion.This issue affects Aldo: from n/a through <= 1.0.10.
GHSA-4c32-xmgj-2g98
High severity vulnerability that affects org.apache.pdfbox:pdfbox
GHSA-4c32-x28m-p8h3
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.
GHSA-4c32-w6c7-77x4
SQL injection when using MySQL/PostgreSQL data checking
GHSA-4c2x-v4q9-wm44
Windows Hyper-V Denial of Service Vulnerability
GHSA-4c2x-qm74-54w5
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
GHSA-4c2x-qgm5-5mrh
The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds."
GHSA-4c2x-g299-mpv8
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
GHSA-4c2w-x5ww-3v7m
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.
GHSA-4c2w-wcw4-8jv9
Jenkins Rundeck Plugin CSRF vulnerability
GHSA-4c2w-v5rq-5mx7
eZ Platform Editor Cross-site Scripting (XSS)
GHSA-4c2v-p982-wgvx
Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."
GHSA-4c2v-95cv-xvxm
Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.
GHSA-4c2q-pqjh-9v54
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
GHSA-4c2q-fwj9-cw6m
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
GHSA-4c2q-9g38-8v79
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4c34-f6qc-56qv The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks | CVSS3: 5.9 | 0% Низкий | около 2 лет назад | |
GHSA-4c33-jjxv-7pfw Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4c33-h9j5-vmhj A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affected is an unknown function of the file /dcwr_entry.php. The manipulation of the argument Date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-4c33-fwgf-qv6r A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4c33-2p78-4q5m Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local File Inclusion.This issue affects Aldo: from n/a through <= 1.0.10. | CVSS3: 8.1 | 0% Низкий | 6 месяцев назад | |
GHSA-4c32-xmgj-2g98 High severity vulnerability that affects org.apache.pdfbox:pdfbox | CVSS3: 7.8 | 4% Низкий | почти 8 лет назад | |
GHSA-4c32-x28m-p8h3 Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption. | 1% Низкий | больше 4 лет назад | ||
GHSA-4c32-w6c7-77x4 SQL injection when using MySQL/PostgreSQL data checking | CVSS3: 8.2 | 1% Низкий | больше 3 лет назад | |
GHSA-4c2x-v4q9-wm44 Windows Hyper-V Denial of Service Vulnerability | CVSS3: 6.5 | 1% Низкий | около 2 лет назад | |
GHSA-4c2x-qm74-54w5 Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4c2x-qgm5-5mrh The AnnotationX.AnnList.1 ActiveX control in Agilent Technologies Feature Extraction allows remote attackers to execute arbitrary code via a crafted object parameter in the Insert function, related to "Index Out-Of-Bounds." | 3% Низкий | больше 4 лет назад | ||
GHSA-4c2x-g299-mpv8 Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution. | CVSS3: 6.4 | 8% Низкий | больше 4 лет назад | |
GHSA-4c2w-x5ww-3v7m Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4c2w-wcw4-8jv9 Jenkins Rundeck Plugin CSRF vulnerability | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4c2w-v5rq-5mx7 eZ Platform Editor Cross-site Scripting (XSS) | больше 2 лет назад | |||
GHSA-4c2v-p982-wgvx Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing." | 2% Низкий | больше 4 лет назад | ||
GHSA-4c2v-95cv-xvxm Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14. | CVSS3: 5.4 | 0% Низкий | 5 месяцев назад | |
GHSA-4c2q-pqjh-9v54 Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-4c2q-fwj9-cw6m Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 4 дня назад | |
GHSA-4c2q-9g38-8v79 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). | CVSS3: 9.9 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу