Количество 365 324
Количество 365 324
GHSA-3wwc-wj68-5rvm
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.
GHSA-3wwc-jjmg-r6gq
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.
GHSA-3wwc-8979-r93x
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
GHSA-3ww9-jwr8-mpg3
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.
GHSA-3ww9-9g46-xw9x
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.
GHSA-3ww8-jw56-9f5h
FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
GHSA-3ww8-8v8c-wrr2
In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.
GHSA-3ww8-82c8-5vpr
Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification.
GHSA-3ww7-w2h2-5c4x
In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.
GHSA-3ww7-qxrg-gc3h
The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.
GHSA-3ww7-mwq4-x3gc
Rejected reason: Not used
GHSA-3ww7-mpcv-cwwh
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
GHSA-3ww7-h83j-f3rc
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
GHSA-3ww5-qm6q-xhcg
The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
GHSA-3ww4-hpff-r8mv
Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.
GHSA-3ww4-gg4f-jr7f
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
GHSA-3ww4-cp53-6g2x
Cross Site Request Forgery in kindeditor
GHSA-3ww4-5jv9-j5gm
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
GHSA-3ww4-5h8f-6c2q
Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
GHSA-3ww4-528c-xcv7
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3wwc-wj68-5rvm Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1. | 3% Низкий | больше 4 лет назад | ||
GHSA-3wwc-jjmg-r6gq Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | CVSS3: 4.4 | 0% Низкий | почти 3 года назад | |
GHSA-3wwc-8979-r93x CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-3ww9-jwr8-mpg3 Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-3ww9-9g46-xw9x The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-3ww8-jw56-9f5h FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing | CVSS3: 5.8 | 0% Низкий | 5 месяцев назад | |
GHSA-3ww8-8v8c-wrr2 In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032. | CVSS3: 6.7 | 0% Низкий | около 4 лет назад | |
GHSA-3ww8-82c8-5vpr Unspecified vulnerability in the Oracle Fusion Middleware component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Process Mgmt and Notification. | 1% Низкий | больше 4 лет назад | ||
GHSA-3ww7-w2h2-5c4x In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3ww7-qxrg-gc3h The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853. | 2% Низкий | больше 4 лет назад | ||
GHSA-3ww7-mwq4-x3gc Rejected reason: Not used | больше 1 года назад | |||
GHSA-3ww7-mpcv-cwwh D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3ww7-h83j-f3rc The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient. | CVSS3: 5.8 | 0% Низкий | около 2 лет назад | |
GHSA-3ww5-qm6q-xhcg The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-3ww4-hpff-r8mv Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-3ww4-gg4f-jr7f Python Cryptography package vulnerable to Bleichenbacher timing oracle attack | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3ww4-cp53-6g2x Cross Site Request Forgery in kindeditor | CVSS3: 8.8 | 1% Низкий | почти 5 лет назад | |
GHSA-3ww4-5jv9-j5gm vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3ww4-5h8f-6c2q Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input. | 1% Низкий | больше 4 лет назад | ||
GHSA-3ww4-528c-xcv7 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data. | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу