Количество 365 324
Количество 365 324
GHSA-3wcq-hf94-333f
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
GHSA-3wcp-pwj7-fwmf
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
GHSA-3wcp-g7h4-2r32
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Moose Moose Elementor Kit allows DOM-Based XSS.This issue affects Moose Elementor Kit: from n/a through 1.0.0.
GHSA-3wcp-fjfh-pw9r
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem".
GHSA-3wcp-53mw-3rwq
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
GHSA-3wcm-x9f4-v99q
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
GHSA-3wcm-vppv-p3q9
IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.
GHSA-3wcm-m2wj-fj25
The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
GHSA-3wcj-rg8q-9cqv
Open redirect in ASP.NET Core
GHSA-3wcj-pc96-v578
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-3wcj-gjvf-fvch
Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior.
GHSA-3wcj-f5mq-gxw2
Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.
GHSA-3wch-cp8h-4vh3
Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.
GHSA-3wch-6hwj-h7f9
Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.
GHSA-3wch-675q-fgx7
In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use after free In dma_release_channel(), check chan->device->privatecnt after call dma_chan_put(). However, dma_chan_put() call dma_device_put() which could release the last reference of the device if the DMA provider is already gone and hence free it. Fixes it by moving dma_chan_put() after the check.
GHSA-3wch-5xm2-547f
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.
GHSA-3wcg-3hq8-89r6
Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.
GHSA-3wcf-94mw-cwgf
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
GHSA-3wcf-84jq-4rxx
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the path '/pdf'.
GHSA-3wcf-67jh-m3g8
XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3wcq-hf94-333f In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3wcp-pwj7-fwmf Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system. | CVSS3: 7.2 | 2% Низкий | больше 1 года назад | |
GHSA-3wcp-g7h4-2r32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Moose Moose Elementor Kit allows DOM-Based XSS.This issue affects Moose Elementor Kit: from n/a through 1.0.0. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-3wcp-fjfh-pw9r The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string "_pub.pem". | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3wcp-53mw-3rwq Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 21 день назад | |
GHSA-3wcm-x9f4-v99q MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn. | 1% Низкий | больше 4 лет назад | ||
GHSA-3wcm-vppv-p3q9 IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3wcm-m2wj-fj25 The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | CVSS3: 7.1 | 1% Низкий | больше 1 года назад | |
GHSA-3wcj-rg8q-9cqv Open redirect in ASP.NET Core | CVSS3: 8.8 | 9% Низкий | больше 4 лет назад | |
GHSA-3wcj-pc96-v578 A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-3wcj-gjvf-fvch Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior. | CVSS3: 4.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-3wcj-f5mq-gxw2 Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3wch-cp8h-4vh3 Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution. | CVSS3: 9.8 | 8% Низкий | больше 4 лет назад | |
GHSA-3wch-6hwj-h7f9 Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-3wch-675q-fgx7 In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use after free In dma_release_channel(), check chan->device->privatecnt after call dma_chan_put(). However, dma_chan_put() call dma_device_put() which could release the last reference of the device if the DMA provider is already gone and hence free it. Fixes it by moving dma_chan_put() after the check. | CVSS3: 7.8 | 0% Низкий | 18 дней назад | |
GHSA-3wch-5xm2-547f An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure. | CVSS3: 9.9 | 2% Низкий | около 2 лет назад | |
GHSA-3wcg-3hq8-89r6 Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3wcf-94mw-cwgf rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts. | CVSS3: 7.5 | 0% Низкий | 4 дня назад | |
GHSA-3wcf-84jq-4rxx An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the path '/pdf'. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3wcf-67jh-m3g8 XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20." | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу