Количество 365 324
Количество 365 324
GHSA-3x4g-259h-5p7c
AMF Improperly Restricts Operations within the Bounds of a Memory Buffer
GHSA-3x4f-24vq-5mhp
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3x4c-pq33-4w3q
Improper authorisation of members discloses room membership to non-members
GHSA-3x4c-7xq6-9pq8
Next.js: Unbounded next/image disk cache growth can exhaust storage
GHSA-3x49-p9xf-cg52
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
GHSA-3x49-h2mv-h459
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
GHSA-3x49-g6rc-c284
LiteDB may deserialize bad JSON on object type using _type
GHSA-3x48-c5fq-3p9x
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.
GHSA-3x48-6948-gjj7
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
GHSA-3x47-w4rx-6pm7
LoLLMS Path Traversal vulnerability
GHSA-3x47-pxw6-fmvq
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.
GHSA-3x47-j85r-45r9
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
GHSA-3x47-hh2w-gf29
Rejected reason: Not used
GHSA-3x46-vw5g-qxj4
Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.
GHSA-3x46-hg82-953f
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
GHSA-3x46-fhq4-2cp2
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
GHSA-3x46-c2g7-344x
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
GHSA-3x46-6xw6-vv9h
Rejected reason: Not used
GHSA-3x46-395m-v3qc
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
GHSA-3x46-2jq5-628v
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x4g-259h-5p7c AMF Improperly Restricts Operations within the Bounds of a Memory Buffer | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-3x4f-24vq-5mhp Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-3x4c-pq33-4w3q Improper authorisation of members discloses room membership to non-members | CVSS3: 3.1 | 1% Низкий | около 5 лет назад | |
GHSA-3x4c-7xq6-9pq8 Next.js: Unbounded next/image disk cache growth can exhaust storage | 1% Низкий | 6 месяцев назад | ||
GHSA-3x49-p9xf-cg52 Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables. | 1% Низкий | больше 4 лет назад | ||
GHSA-3x49-h2mv-h459 Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-3x49-g6rc-c284 LiteDB may deserialize bad JSON on object type using _type | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3x48-c5fq-3p9x The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
GHSA-3x48-6948-gjj7 Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs." | 5% Низкий | больше 4 лет назад | ||
GHSA-3x47-w4rx-6pm7 LoLLMS Path Traversal vulnerability | CVSS3: 9.8 | 28% Средний | около 2 лет назад | |
GHSA-3x47-pxw6-fmvq Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-3x47-j85r-45r9 Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3x47-hh2w-gf29 Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3x46-vw5g-qxj4 Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb. | 1% Низкий | больше 4 лет назад | ||
GHSA-3x46-hg82-953f A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-3x46-fhq4-2cp2 In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x46-c2g7-344x F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | CVSS3: 8.8 | 13% Средний | больше 2 лет назад | |
GHSA-3x46-6xw6-vv9h Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3x46-395m-v3qc Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135. | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3x46-2jq5-628v Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776. | 20% Средний | больше 4 лет назад |
Уязвимостей на страницу