Количество 367 277
Количество 367 277
GHSA-458r-h248-29c5
CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
GHSA-458r-3fhx-pxqf
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.
GHSA-458q-r95h-835g
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-458q-p8pq-fq89
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and C...
GHSA-458q-p5fc-j68h
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.
GHSA-458q-gp96-jqrm
IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721.
GHSA-458q-g468-2frr
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.
GHSA-458q-8qpc-ggh3
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.
GHSA-458q-4x98-hjwr
An unauthenticated attacker can hijack other users' devices and potentially control them.
GHSA-458p-jh3w-vf34
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.
GHSA-458p-h259-m4hv
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-458m-m9vv-frq3
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
GHSA-458j-xx4x-4375
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
GHSA-458j-vj9v-25r8
Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.
GHSA-458h-wv48-fq75
Keycloak vulnerable to cross-site scripting via the state parameter
GHSA-458h-vprj-79h8
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
GHSA-458h-5hgf-82mf
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
GHSA-458h-3v6h-9r7g
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
GHSA-458g-vvmf-jfgq
Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.
GHSA-458g-q4fh-mj6r
Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-458r-h248-29c5 CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад | |
GHSA-458r-3fhx-pxqf Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0. | CVSS3: 9.3 | 0% Низкий | 6 месяцев назад | |
GHSA-458q-r95h-835g SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-458q-p8pq-fq89 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and C... | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-458q-p5fc-j68h The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-458q-gp96-jqrm IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721. | CVSS3: 7.8 | 3% Низкий | больше 4 лет назад | |
GHSA-458q-g468-2frr Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6. | CVSS3: 8.1 | 0% Низкий | 8 месяцев назад | |
GHSA-458q-8qpc-ggh3 OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-458q-4x98-hjwr An unauthenticated attacker can hijack other users' devices and potentially control them. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-458p-jh3w-vf34 Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-458p-h259-m4hv Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 8 месяцев назад | |||
GHSA-458m-m9vv-frq3 Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. | CVSS3: 7.5 | 0% Низкий | 7 дней назад | |
GHSA-458j-xx4x-4375 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
GHSA-458j-vj9v-25r8 Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-458h-wv48-fq75 Keycloak vulnerable to cross-site scripting via the state parameter | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-458h-vprj-79h8 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-458h-5hgf-82mf Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium) | CVSS3: 8.1 | 0% Низкий | 13 дней назад | |
GHSA-458h-3v6h-9r7g Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-458g-vvmf-jfgq Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-458g-q4fh-mj6r Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header | CVSS3: 7.2 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу