Количество 362 328
Количество 362 328
GHSA-3h8x-jv2f-mmvp
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-3h8w-7jg4-hcrw
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
GHSA-3h8v-g624-hvxg
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.
GHSA-3h8r-hv7f-jgcx
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.
GHSA-3h8r-f622-g36q
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
GHSA-3h8r-9w82-hxmh
A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.
GHSA-3h8r-96mm-7vvg
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
GHSA-3h8r-6x68-6v9m
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.
GHSA-3h8q-f835-m698
A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3h8p-v7v7-3333
Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.
GHSA-3h8p-48px-cj7r
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263113 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3h8p-2v2p-mc5x
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
GHSA-3h8m-q4x3-3fhw
The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
GHSA-3h8m-mvxw-xrmm
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential corruption when moving a directory F2FS has the same issue in ext4_rename causing crash revealed by xfstests/generic/707. See also commit 0813299c586b ("ext4: Fix possible corruption when moving a directory")
GHSA-3h8m-483j-7xxm
Heap out of bounds read in `RequantizationRange`
GHSA-3h8h-mjhw-3m3h
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
GHSA-3h8h-469q-248f
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
GHSA-3h8g-q3cw-mr42
Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.
GHSA-3h8c-h67v-4vg7
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.
GHSA-3h89-j8rf-vq88
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3h8x-jv2f-mmvp A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-3h8w-7jg4-hcrw upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors. | CVSS3: 4.9 | 15% Средний | больше 4 лет назад | |
GHSA-3h8v-g624-hvxg TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-3h8r-hv7f-jgcx The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | 9% Низкий | больше 4 лет назад | ||
GHSA-3h8r-f622-g36q The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3h8r-9w82-hxmh A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-3h8r-96mm-7vvg The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-3h8r-6x68-6v9m Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL. | 2% Низкий | больше 4 лет назад | ||
GHSA-3h8q-f835-m698 A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
GHSA-3h8p-v7v7-3333 Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control. | 43% Средний | больше 4 лет назад | ||
GHSA-3h8p-48px-cj7r A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263113 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.7 | 7% Низкий | больше 2 лет назад | |
GHSA-3h8p-2v2p-mc5x An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3h8m-q4x3-3fhw The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading. | CVSS3: 3.3 | 0% Низкий | около 4 лет назад | |
GHSA-3h8m-mvxw-xrmm In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential corruption when moving a directory F2FS has the same issue in ext4_rename causing crash revealed by xfstests/generic/707. See also commit 0813299c586b ("ext4: Fix possible corruption when moving a directory") | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-3h8m-483j-7xxm Heap out of bounds read in `RequantizationRange` | CVSS3: 2.5 | 0% Низкий | больше 5 лет назад | |
GHSA-3h8h-mjhw-3m3h The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check. | 0% Низкий | около 4 лет назад | ||
GHSA-3h8h-469q-248f Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-3h8g-q3cw-mr42 Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3h8c-h67v-4vg7 Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3h89-j8rf-vq88 radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations. | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу