Количество 365 060
Количество 365 060
GHSA-3v7p-mx8w-xf2h
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-3v7p-hjjf-gqp8
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home directory paths in /etc/passwd entries to execute arbitrary commands on the analyst's host system.
GHSA-3v7p-2jr8-qj72
In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.
GHSA-3v7m-rv2r-mcp9
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."
GHSA-3v7m-qg4x-58h9
AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
GHSA-3v7m-2jrh-vc93
Froxlor vulnerable to Argument Injection
GHSA-3v7g-82fr-x624
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.
GHSA-3v7g-4pg3-7r6j
OS Command injection in Apache Airflow
GHSA-3v7f-rjgx-9grq
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.
GHSA-3v7f-ppjx-349f
Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
GHSA-3v7f-822w-wj7f
jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Log directory configuration field. Attackers can paste a buffer of 5000 characters into the Log directory input, then click Start to trigger a crash that terminates the server process.
GHSA-3v7f-55p6-f55p
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
GHSA-3v7c-xw2c-76j5
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.
GHSA-3v7c-v9wf-3c7v
There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.
GHSA-3v7c-p24m-p9gr
Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP address of the router. Repeated crashes of the rpd daemon can result in an extended denial of service condition. This issue only affects devices running Junos OS 16.1R1 and services releases based off of 16.1R1 (e.g. 16.1R1-S1, 16.1R1-S2, 16.1R1-S3). No prior versions of Junos OS are affected by this vulnerability, and this issue was resolved in Junos OS 16.2 prior to 16.2R1. No other Juniper Networks products or platforms are affected by this issue. This issue was found during internal product security testing.
GHSA-3v7c-g8p3-w3h6
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
GHSA-3v79-q7ph-j75h
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
GHSA-3v79-p2r2-6744
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a through 3.1.
GHSA-3v79-m2cg-89ww
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
GHSA-3v79-5f35-jq7j
Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3v7p-mx8w-xf2h Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-3v7p-hjjf-gqp8 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home directory paths in /etc/passwd entries to execute arbitrary commands on the analyst's host system. | CVSS3: 7.8 | 1% Низкий | 10 дней назад | |
GHSA-3v7p-2jr8-qj72 In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3v7m-rv2r-mcp9 A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp." | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-3v7m-qg4x-58h9 AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
GHSA-3v7m-2jrh-vc93 Froxlor vulnerable to Argument Injection | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3v7g-82fr-x624 Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-3v7g-4pg3-7r6j OS Command injection in Apache Airflow | CVSS3: 8.8 | 78% Высокий | больше 4 лет назад | |
GHSA-3v7f-rjgx-9grq A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-3v7f-ppjx-349f Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header. | 2% Низкий | больше 4 лет назад | ||
GHSA-3v7f-822w-wj7f jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Log directory configuration field. Attackers can paste a buffer of 5000 characters into the Log directory input, then click Start to trigger a crash that terminates the server process. | CVSS3: 5.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3v7f-55p6-f55p Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-3v7c-xw2c-76j5 ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
GHSA-3v7c-v9wf-3c7v There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered. | CVSS3: 5.7 | 0% Низкий | больше 2 лет назад | |
GHSA-3v7c-p24m-p9gr Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP address of the router. Repeated crashes of the rpd daemon can result in an extended denial of service condition. This issue only affects devices running Junos OS 16.1R1 and services releases based off of 16.1R1 (e.g. 16.1R1-S1, 16.1R1-S2, 16.1R1-S3). No prior versions of Junos OS are affected by this vulnerability, and this issue was resolved in Junos OS 16.2 prior to 16.2R1. No other Juniper Networks products or platforms are affected by this issue. This issue was found during internal product security testing. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3v7c-g8p3-w3h6 NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure. | CVSS3: 7.8 | 1% Низкий | около 1 месяца назад | |
GHSA-3v79-q7ph-j75h MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution | CVSS3: 9.6 | 1% Низкий | больше 2 лет назад | |
GHSA-3v79-p2r2-6744 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a through 3.1. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-3v79-m2cg-89ww Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE | CVSS3: 8 | около 2 месяцев назад | ||
GHSA-3v79-5f35-jq7j Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу