Количество 367 277
Количество 367 277
GHSA-456m-322m-v58x
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-456j-pp8g-p3qx
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.
GHSA-456j-c4vg-62wg
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
GHSA-456h-6frm-3fqv
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.
GHSA-456g-pvm5-mvgm
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
GHSA-456g-p3f3-7247
An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.
GHSA-456g-4jpc-gj7q
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-456f-p7fp-957g
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
GHSA-456c-2rgc-q4mf
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
GHSA-4569-2jp2-r7vf
A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.
GHSA-4568-46j5-889r
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
GHSA-4567-qcr7-fjv3
Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)
GHSA-4567-7fw8-972r
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.
GHSA-4565-r4x7-hg8j
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
GHSA-4565-7jh8-9r34
Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.
GHSA-4564-pvr2-qq4h
OpenClaw: Prevent shell injection in macOS keychain credential write
GHSA-4564-2f76-rv6p
Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
GHSA-4563-rxxv-48gh
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
GHSA-4563-pqrg-7hcj
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
GHSA-4563-6q26-9q79
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-456m-322m-v58x Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-456j-pp8g-p3qx Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-456j-c4vg-62wg Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-456h-6frm-3fqv Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-456g-pvm5-mvgm The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-456g-p3f3-7247 An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-456g-4jpc-gj7q Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 8 месяцев назад | |||
GHSA-456f-p7fp-957g Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. | CVSS3: 8.3 | 37% Средний | больше 1 года назад | |
GHSA-456c-2rgc-q4mf cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). | 0% Низкий | больше 4 лет назад | ||
GHSA-4569-2jp2-r7vf A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command. | CVSS3: 8.8 | 11% Средний | больше 4 лет назад | |
GHSA-4568-46j5-889r kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-4567-qcr7-fjv3 Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low) | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-4567-7fw8-972r In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected. | 1% Низкий | больше 4 лет назад | ||
GHSA-4565-r4x7-hg8j Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation | 0% Низкий | 3 месяца назад | ||
GHSA-4565-7jh8-9r34 Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $. | 3% Низкий | больше 4 лет назад | ||
GHSA-4564-pvr2-qq4h OpenClaw: Prevent shell injection in macOS keychain credential write | CVSS3: 7.6 | 1% Низкий | 7 месяцев назад | |
GHSA-4564-2f76-rv6p Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability." | 29% Средний | больше 4 лет назад | ||
GHSA-4563-rxxv-48gh An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-4563-pqrg-7hcj SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | 1% Низкий | больше 4 лет назад | ||
GHSA-4563-6q26-9q79 The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу