Количество 365 324
Количество 365 324
GHSA-3wfw-hw9j-3p3m
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.
GHSA-3wfw-cf7h-38c7
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials.
GHSA-3wfv-3cfc-9mjc
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
GHSA-3wfr-9gjx-63gf
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
GHSA-3wfq-h43q-w8hw
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.
GHSA-3wfq-4hqg-3c4g
In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890242
GHSA-3wfp-9jx5-5xmc
The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
GHSA-3wfp-98cg-vgm9
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
GHSA-3wfp-66x3-wgq2
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148.
GHSA-3wfp-4xf2-2wr9
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3wfp-4rwx-xmxg
A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248255.
GHSA-3wfp-253j-5jxv
SSRF & Credentials Leak
GHSA-3wfm-93m9-mc3c
An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.
GHSA-3wfj-vh84-732p
Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ
GHSA-3wfj-3x8q-hrpg
Kubean vulnerable to cluster-level privilege escalation
GHSA-3wfh-rjpp-24cr
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' parameter in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-3wfh-qwcv-pvx7
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.
GHSA-3wfh-qf63-pj8r
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655.
GHSA-3wfh-mxpq-hxqh
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.
GHSA-3wfh-36rx-9537
Timing Attack Vulnerability in SCRAM Authentication
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3wfw-hw9j-3p3m Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules. | CVSS3: 6.4 | 0% Низкий | 7 месяцев назад | |
GHSA-3wfw-cf7h-38c7 A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration files on an affected system. A successful exploit could allow the attacker to view MongoDB credentials. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
GHSA-3wfv-3cfc-9mjc In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. | CVSS3: 6.1 | 59% Средний | больше 3 лет назад | |
GHSA-3wfr-9gjx-63gf iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script. | 0% Низкий | больше 4 лет назад | ||
GHSA-3wfq-h43q-w8hw IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658. | 1% Низкий | больше 4 лет назад | ||
GHSA-3wfq-4hqg-3c4g In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890242 | 1% Низкий | больше 4 лет назад | ||
GHSA-3wfp-9jx5-5xmc The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | CVSS3: 4.8 | 1% Низкий | почти 4 года назад | |
GHSA-3wfp-98cg-vgm9 Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. | CVSS3: 9.8 | 24% Средний | больше 4 лет назад | |
GHSA-3wfp-66x3-wgq2 Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3wfp-4xf2-2wr9 A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-3wfp-4rwx-xmxg A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248255. | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3wfp-253j-5jxv SSRF & Credentials Leak | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3wfm-93m9-mc3c An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service. | 1% Низкий | больше 4 лет назад | ||
GHSA-3wfj-vh84-732p Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ | CVSS3: 7.5 | 13% Средний | больше 4 лет назад | |
GHSA-3wfj-3x8q-hrpg Kubean vulnerable to cluster-level privilege escalation | CVSS3: 6 | 0% Низкий | около 2 лет назад | |
GHSA-3wfh-rjpp-24cr The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' parameter in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 4 месяца назад | |
GHSA-3wfh-qwcv-pvx7 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3wfh-qf63-pj8r A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | CVSS3: 7.5 | 11% Средний | больше 4 лет назад | |
GHSA-3wfh-mxpq-hxqh Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3wfh-36rx-9537 Timing Attack Vulnerability in SCRAM Authentication | 1% Низкий | 12 месяцев назад |
Уязвимостей на страницу