Количество 369 608
Количество 369 608
GHSA-486g-jg8g-q4pg
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.
GHSA-486g-47cc-8wxf
aiocpa contains credential harvesting code
GHSA-486g-3323-7948
Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.
GHSA-486f-hjj9-9vhh
Inefficient Regular Expression Complexity in Loofah
GHSA-486c-vrv4-hh35
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
GHSA-486c-fgp8-q4mj
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
GHSA-4869-x4pr-q22x
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
GHSA-4869-v738-xvvg
2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
GHSA-4869-ghp2-7x5q
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.
GHSA-4868-5x3w-95q3
Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php.
GHSA-4866-p686-25f3
DrayTek Vigor2960 1.3.1_Beta; Vigor3900 1.4.4_Beta; and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.
GHSA-4863-57r9-m6xc
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4.
GHSA-4862-x8vr-278v
IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.
GHSA-485w-vv83-53fx
Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.
GHSA-485w-jm59-qvxp
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.
GHSA-485w-3qw7-xvjq
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
GHSA-485v-wc7x-92fx
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.
GHSA-485v-639h-vm9r
A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
GHSA-485v-466m-9mjv
In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.
GHSA-485r-rp8v-998v
Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-486g-jg8g-q4pg Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php. | 13% Средний | больше 4 лет назад | ||
GHSA-486g-47cc-8wxf aiocpa contains credential harvesting code | почти 2 года назад | |||
GHSA-486g-3323-7948 Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-486f-hjj9-9vhh Inefficient Regular Expression Complexity in Loofah | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-486c-vrv4-hh35 SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-486c-fgp8-q4mj A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5. | CVSS3: 7.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4869-x4pr-q22x PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | CVSS3: 9.8 | 3 месяца назад | ||
GHSA-4869-v738-xvvg 2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-4869-ghp2-7x5q Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers. | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-4868-5x3w-95q3 Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-4866-p686-25f3 DrayTek Vigor2960 1.3.1_Beta; Vigor3900 1.4.4_Beta; and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. | CVSS3: 9.8 | 100% Критический | больше 4 лет назад | |
GHSA-4863-57r9-m6xc Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-4862-x8vr-278v IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632. | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
GHSA-485w-vv83-53fx Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request. | 3% Низкий | больше 4 лет назад | ||
GHSA-485w-jm59-qvxp Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-485w-3qw7-xvjq The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document. | 1% Низкий | больше 4 лет назад | ||
GHSA-485v-wc7x-92fx An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service. | CVSS3: 6.2 | 0% Низкий | 3 месяца назад | |
GHSA-485v-639h-vm9r A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-485v-466m-9mjv In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-485r-rp8v-998v Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability | CVSS3: 8.1 | 2% Низкий | около 3 лет назад |
Уязвимостей на страницу