Количество 362 078
Количество 362 078
GHSA-3ghv-w9fm-536c
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
GHSA-3ghv-qqmp-p6c4
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.
GHSA-3ghv-75mw-fc8f
Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
GHSA-3ghq-rfpw-jhqx
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.
GHSA-3ghq-g9vp-wwq2
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
GHSA-3ghq-53cj-qqmp
An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.
GHSA-3ghq-3f49-fr98
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
GHSA-3ghp-8r47-4gj4
FoundationAgents MetaGPT vulnerable to eval injection
GHSA-3ghp-2qxv-j2hr
Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.
GHSA-3ghj-wv9w-7vp9
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
GHSA-3ghj-f9w6-vh8h
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.
GHSA-3ghh-rm9h-rjcv
Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.
GHSA-3ghh-mq29-47m6
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
GHSA-3ghh-4p87-43pm
An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling the PC unit and accessing the device's flash memory. The Alaris 8015 PC unit, Version 9.7, and the 8000 PC unit store wireless network authentication credentials and other sensitive technical data on internal flash memory. Accessing the internal flash memory of the affected device would require special tools to extract data and carrying out this attack at a healthcare facility would increase the likelihood of detection.
GHSA-3ghg-3787-w2xr
Spree API has Unauthenticated IDOR - Guest Address
GHSA-3ghf-mqfr-9xvw
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.
GHSA-3ghf-f72w-2g9p
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
GHSA-3ghf-chw5-4mxm
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
GHSA-3ghc-cw76-h292
Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
GHSA-3ghc-2486-hrxh
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then it is possible that a race condition occurs if genpd tries to power them on in the same time. The same is valid for powering them off before unregistering them from genpd. Attempt to fix race conditions by first removing the domains from genpd and *after that* powering down domains. Also first power up the domains and *after that* register them to genpd.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3ghv-w9fm-536c IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3ghv-qqmp-p6c4 The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account. | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
GHSA-3ghv-75mw-fc8f Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3ghq-rfpw-jhqx Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user. | CVSS3: 8.8 | 24% Средний | 11 месяцев назад | |
GHSA-3ghq-g9vp-wwq2 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. | CVSS3: 5.9 | 0% Низкий | почти 3 года назад | |
GHSA-3ghq-53cj-qqmp An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference. | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3ghq-3f49-fr98 Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-3ghp-8r47-4gj4 FoundationAgents MetaGPT vulnerable to eval injection | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
GHSA-3ghp-2qxv-j2hr Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-3ghj-wv9w-7vp9 Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack. | CVSS3: 9.8 | 4% Низкий | больше 2 лет назад | |
GHSA-3ghj-f9w6-vh8h SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-3ghh-rm9h-rjcv Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information. | 6% Низкий | больше 4 лет назад | ||
GHSA-3ghh-mq29-47m6 Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters. | 2% Низкий | больше 4 лет назад | ||
GHSA-3ghh-4p87-43pm An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling the PC unit and accessing the device's flash memory. The Alaris 8015 PC unit, Version 9.7, and the 8000 PC unit store wireless network authentication credentials and other sensitive technical data on internal flash memory. Accessing the internal flash memory of the affected device would require special tools to extract data and carrying out this attack at a healthcare facility would increase the likelihood of detection. | CVSS3: 4.9 | 1% Низкий | больше 4 лет назад | |
GHSA-3ghg-3787-w2xr Spree API has Unauthenticated IDOR - Guest Address | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-3ghf-mqfr-9xvw A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272. | CVSS3: 6.3 | 1% Низкий | больше 3 лет назад | |
GHSA-3ghf-f72w-2g9p AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request | 7% Низкий | больше 4 лет назад | ||
GHSA-3ghf-chw5-4mxm The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3ghc-cw76-h292 Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-3ghc-2486-hrxh In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then it is possible that a race condition occurs if genpd tries to power them on in the same time. The same is valid for powering them off before unregistering them from genpd. Attempt to fix race conditions by first removing the domains from genpd and *after that* powering down domains. Also first power up the domains and *after that* register them to genpd. | CVSS3: 4.7 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу