Количество 364 463
Количество 364 463
GHSA-3q26-rw63-5772
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
GHSA-3q26-f695-pp76
@cyanheads/git-mcp-server vulnerable to command injection in several tools
GHSA-3q25-m4x5-9jh7
An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
GHSA-3q24-wf35-56h6
IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.
GHSA-3q24-rrgq-j66h
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
GHSA-3q23-2j2r-mmw3
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
GHSA-3q22-68gw-x3mq
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
GHSA-3pxx-76hx-4rw2
Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.
GHSA-3pxv-j5r5-v5qh
In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...
GHSA-3pxv-834r-692c
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Quanzo quanzo allows PHP Local File Inclusion.This issue affects Quanzo: from n/a through <= 1.0.10.
GHSA-3pxv-7cmr-fjr4
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
GHSA-3pxr-wpfc-92h9
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
GHSA-3pxr-vgjw-q3f8
Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
GHSA-3pxr-3j7f-c35j
Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.
GHSA-3pxq-xg4j-rgqx
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
GHSA-3pxq-f3cp-jmxp
OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows
GHSA-3pxq-5cc9-p3hw
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.
GHSA-3pxq-4mq2-m2mc
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.
GHSA-3pxp-pwrp-2w6f
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.
GHSA-3pxp-6963-46r9
Command Injection in pdfinfojs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3q26-rw63-5772 There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-3q26-f695-pp76 @cyanheads/git-mcp-server vulnerable to command injection in several tools | CVSS3: 7.5 | 27% Средний | около 1 года назад | |
GHSA-3q25-m4x5-9jh7 An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users. | 3% Низкий | больше 4 лет назад | ||
GHSA-3q24-wf35-56h6 IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service. | CVSS3: 6 | 0% Низкий | больше 1 года назад | |
GHSA-3q24-rrgq-j66h Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-3q23-2j2r-mmw3 Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | CVSS3: 8.8 | 12% Средний | больше 1 года назад | |
GHSA-3q22-68gw-x3mq IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | CVSS3: 5.9 | 0% Низкий | 11 месяцев назад | |
GHSA-3pxx-76hx-4rw2 Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411. | 3% Низкий | больше 4 лет назад | ||
GHSA-3pxv-j5r5-v5qh In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee... | CVSS3: 5.5 | 0% Низкий | 12 месяцев назад | |
GHSA-3pxv-834r-692c Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Quanzo quanzo allows PHP Local File Inclusion.This issue affects Quanzo: from n/a through <= 1.0.10. | CVSS3: 8.1 | 0% Низкий | 6 месяцев назад | |
GHSA-3pxv-7cmr-fjr4 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | 1% Низкий | 5 месяцев назад | ||
GHSA-3pxr-wpfc-92h9 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
GHSA-3pxr-vgjw-q3f8 Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0% Низкий | больше 4 лет назад | ||
GHSA-3pxr-3j7f-c35j Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | CVSS3: 5.4 | 2% Низкий | около 2 лет назад | |
GHSA-3pxq-xg4j-rgqx An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-3pxq-f3cp-jmxp OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-3pxq-5cc9-p3hw Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address. | 2% Низкий | больше 4 лет назад | ||
GHSA-3pxq-4mq2-m2mc The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters. | 5% Низкий | больше 4 лет назад | ||
GHSA-3pxp-pwrp-2w6f Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack. | 3% Низкий | больше 4 лет назад | ||
GHSA-3pxp-6963-46r9 Command Injection in pdfinfojs | CVSS3: 9.8 | 5% Низкий | около 8 лет назад |
Уязвимостей на страницу