Количество 367 277
Количество 367 277
GHSA-44w3-wrmw-j9hx
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
GHSA-44w3-qvp9-4hh4
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
GHSA-44w3-4x9p-xmff
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
GHSA-44w2-xrgw-gqvj
Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.
GHSA-44w2-crmp-vc4v
Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.
GHSA-44w2-cgm4-695p
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.
GHSA-44w2-c6gq-2xxx
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
GHSA-44vx-q8jj-wcwm
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
GHSA-44vx-c3xh-577j
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.
GHSA-44vw-x4jf-3q2f
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
GHSA-44vw-5m8p-p6fc
Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.
GHSA-44vv-qwrx-c34r
Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
GHSA-44vv-mm86-7cg6
phpMyAdmin server-side request forgery (SSRF)
GHSA-44vv-j7c4-9vf4
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
GHSA-44vv-6vcv-9h7r
Windows Telephony Service Remote Code Execution Vulnerability
GHSA-44vv-4w2p-9wqf
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.
GHSA-44vv-2mpg-8hv5
Microsoft Office OneNote Remote Code Execution Vulnerability
GHSA-44vr-rwwj-p88h
Shescape vulnerable to insufficient escaping of whitespace
GHSA-44vr-phh9-75gf
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.
GHSA-44vr-jgwf-45qh
Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-44w3-wrmw-j9hx IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970. | CVSS3: 8.5 | 1% Низкий | больше 4 лет назад | |
GHSA-44w3-qvp9-4hh4 In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-44w3-4x9p-xmff The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-44w2-xrgw-gqvj Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695. | 1% Низкий | больше 4 лет назад | ||
GHSA-44w2-crmp-vc4v Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-44w2-cgm4-695p A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined. | 1% Низкий | около 1 года назад | ||
GHSA-44w2-c6gq-2xxx IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-44vx-q8jj-wcwm Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | 1% Низкий | больше 4 лет назад | ||
GHSA-44vx-c3xh-577j Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5. | CVSS3: 6.1 | 0% Низкий | 11 месяцев назад | |
GHSA-44vw-x4jf-3q2f MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-44vw-5m8p-p6fc Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action. | 2% Низкий | больше 4 лет назад | ||
GHSA-44vv-qwrx-c34r Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-44vv-mm86-7cg6 phpMyAdmin server-side request forgery (SSRF) | CVSS3: 8.6 | 2% Низкий | больше 4 лет назад | |
GHSA-44vv-j7c4-9vf4 Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | CVSS3: 6.3 | 0% Низкий | почти 3 года назад | |
GHSA-44vv-6vcv-9h7r Windows Telephony Service Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-44vv-4w2p-9wqf In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-44vv-2mpg-8hv5 Microsoft Office OneNote Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 2 лет назад | |
GHSA-44vr-rwwj-p88h Shescape vulnerable to insufficient escaping of whitespace | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-44vr-phh9-75gf Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-44vr-jgwf-45qh Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу