Количество 366 653
Количество 366 653
GHSA-4378-f9mm-5685
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions.
GHSA-4377-w6r6-fpff
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.
GHSA-4377-hq3v-hgqh
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496
GHSA-4377-g9q2-3wh5
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.
GHSA-4376-ff9v-5wj2
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-4376-93v6-4h5m
A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution.
GHSA-4375-54m2-mm7p
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.
GHSA-4374-q6w2-q795
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-4374-p667-p6c8
HTTP/2 rapid reset can cause excessive work in net/http
GHSA-4374-j4qr-5p28
components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.
GHSA-4374-6xfq-3wjw
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.
GHSA-4374-5gxx-h9r3
Microsoft Exchange Server Information Disclosure Vulnerability.
GHSA-4373-qwqg-vgwm
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
GHSA-4373-44w4-v53r
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions.
GHSA-4372-pgmc-78wq
Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA-436x-j7j9-9jv7
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
GHSA-436x-9fhf-jq78
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.
GHSA-436w-wv2w-q46v
An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
GHSA-436v-rwrw-9mfh
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.
GHSA-436v-jg82-p533
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4378-f9mm-5685 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= 6.5.3 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-4377-w6r6-fpff A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter. | CVSS3: 6.6 | 0% Низкий | почти 2 года назад | |
GHSA-4377-hq3v-hgqh In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496 | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-4377-g9q2-3wh5 Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-4376-ff9v-5wj2 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 15 дней назад | |||
GHSA-4376-93v6-4h5m A use after free issue was addressed with improved memory management. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution. | 3% Низкий | больше 4 лет назад | ||
GHSA-4375-54m2-mm7p A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by adding specific strings to multiple configuration fields. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4374-q6w2-q795 A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-4374-p667-p6c8 HTTP/2 rapid reset can cause excessive work in net/http | CVSS3: 7.5 | 4% Низкий | почти 3 года назад | |
GHSA-4374-j4qr-5p28 components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-4374-6xfq-3wjw The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later. | CVSS3: 9.8 | 5% Низкий | 7 месяцев назад | |
GHSA-4374-5gxx-h9r3 Microsoft Exchange Server Information Disclosure Vulnerability. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-4373-qwqg-vgwm Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression. | 33% Средний | больше 4 лет назад | ||
GHSA-4373-44w4-v53r Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-4372-pgmc-78wq Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-436x-j7j9-9jv7 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-436x-9fhf-jq78 The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. | 20% Средний | больше 4 лет назад | ||
GHSA-436w-wv2w-q46v An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile | 0% Низкий | больше 4 лет назад | ||
GHSA-436v-rwrw-9mfh Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-436v-jg82-p533 Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE | CVSS3: 9.8 | 2% Низкий | 7 месяцев назад |
Уязвимостей на страницу