Количество 366 653
Количество 366 653
GHSA-438w-wmw3-rcp9
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-438w-rjj9-5fjf
Cross-site Scripting in Jenkins Repository Connector Plugin
GHSA-438w-mprg-3r4x
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).
GHSA-438r-9269-8f2c
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.
GHSA-438q-mx46-fpm4
In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-438q-mm87-r2p9
A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
GHSA-438q-jx8f-cccv
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
GHSA-438p-qhhr-8gxm
Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.
GHSA-438p-hr89-q323
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.
GHSA-438p-f52x-jj25
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection.
GHSA-438m-xgcg-7xx6
SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.
GHSA-438m-xg9x-7hw2
C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.
GHSA-438m-gffq-9866
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
GHSA-438m-6mhw-hq5w
Mautic vulnerable to secret data extraction via elfinder
GHSA-438j-gj6m-538p
In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531
GHSA-438j-8gh2-h5w4
The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
GHSA-438j-3c2r-rp4p
Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.
GHSA-438j-26hg-98wc
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.
GHSA-438h-h6xr-v2p3
In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations
GHSA-438h-3pc3-hx6p
Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-438w-wmw3-rcp9 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | 10 дней назад | |||
GHSA-438w-rjj9-5fjf Cross-site Scripting in Jenkins Repository Connector Plugin | CVSS3: 8 | 1% Низкий | около 4 лет назад | |
GHSA-438w-mprg-3r4x The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default). | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
GHSA-438r-9269-8f2c SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-438q-mx46-fpm4 In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.4 | 0% Низкий | больше 2 лет назад | |
GHSA-438q-mm87-r2p9 A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session. | CVSS3: 8.7 | 0% Низкий | 5 месяцев назад | |
GHSA-438q-jx8f-cccv Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-438p-qhhr-8gxm Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio. | 1% Низкий | больше 4 лет назад | ||
GHSA-438p-hr89-q323 In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally. | CVSS3: 9.8 | 1% Низкий | 26 дней назад | |
GHSA-438p-f52x-jj25 An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-438m-xgcg-7xx6 SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action. | 1% Низкий | больше 4 лет назад | ||
GHSA-438m-xg9x-7hw2 C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements. | CVSS3: 6.2 | 0% Низкий | около 2 лет назад | |
GHSA-438m-gffq-9866 Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-438m-6mhw-hq5w Mautic vulnerable to secret data extraction via elfinder | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-438j-gj6m-538p In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531 | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-438j-8gh2-h5w4 The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-438j-3c2r-rp4p Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. | CVSS3: 6.2 | 0% Низкий | 11 месяцев назад | |
GHSA-438j-26hg-98wc SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not. | 1% Низкий | больше 4 лет назад | ||
GHSA-438h-h6xr-v2p3 In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-438h-3pc3-hx6p Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу