Количество 361 446
Количество 361 446
GHSA-3f84-j5xw-c967
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
GHSA-3f84-gf8q-ggcq
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
GHSA-3f84-67w6-pvm9
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
GHSA-3f83-v3jg-8cf4
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
GHSA-3f82-v3qw-53q7
Passwords transmitted in plain text by Jenkins Stash Branch Parameter Plugin
GHSA-3f7x-wq77-2867
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.
GHSA-3f7x-wmqw-jp3f
In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805.
GHSA-3f7x-rf2q-c7q4
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
GHSA-3f7x-qm4p-6qjv
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
GHSA-3f7x-m7w7-vqr9
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
GHSA-3f7x-cmp2-m6m3
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.
GHSA-3f7x-84v6-xqm2
Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.
GHSA-3f7x-5hc9-j6v5
URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.
GHSA-3f7x-54cr-7w35
Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter.
GHSA-3f7x-25p9-vp9m
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922.
GHSA-3f7w-p8vr-4v5f
pyLoad allows upload to arbitrary folder lead to RCE
GHSA-3f7w-jxww-c39p
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
GHSA-3f7w-8rr8-f37f
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GHSA-3f7w-7j77-73m5
The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The plugin allows administrators (via its settings) to extend the ability to submit events to unauthenticated users, which would allow unauthenticated attackers to exploit this vulnerability.
GHSA-3f7v-qx94-666m
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3f84-j5xw-c967 UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3f84-gf8q-ggcq IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation. | 1% Низкий | больше 4 лет назад | ||
GHSA-3f84-67w6-pvm9 The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | 18% Средний | больше 4 лет назад | ||
GHSA-3f83-v3jg-8cf4 PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-3f82-v3qw-53q7 Passwords transmitted in plain text by Jenkins Stash Branch Parameter Plugin | CVSS3: 3.1 | 1% Низкий | около 4 лет назад | |
GHSA-3f7x-wq77-2867 Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter. | 10% Средний | больше 4 лет назад | ||
GHSA-3f7x-wmqw-jp3f In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310805; Issue ID: ALPS07310805. | CVSS3: 6.7 | 0% Низкий | почти 3 года назад | |
GHSA-3f7x-rf2q-c7q4 The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805. | 15% Средний | больше 4 лет назад | ||
GHSA-3f7x-qm4p-6qjv cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577). | 1% Низкий | около 4 лет назад | ||
GHSA-3f7x-m7w7-vqr9 Memory corruption when processing camera sensor input/output control codes with invalid output buffers. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-3f7x-cmp2-m6m3 An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3f7x-84v6-xqm2 Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3f7x-5hc9-j6v5 URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24. | 0% Низкий | 10 месяцев назад | ||
GHSA-3f7x-54cr-7w35 Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter. | CVSS3: 5 | 26% Средний | больше 1 года назад | |
GHSA-3f7x-25p9-vp9m PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922. | 6% Низкий | больше 4 лет назад | ||
GHSA-3f7w-p8vr-4v5f pyLoad allows upload to arbitrary folder lead to RCE | CVSS3: 9.1 | 1% Низкий | больше 2 лет назад | |
GHSA-3f7w-jxww-c39p Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H). | CVSS3: 5.5 | 3% Низкий | около 4 лет назад | |
GHSA-3f7w-8rr8-f37f GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read | CVSS3: 8.1 | 17 дней назад | ||
GHSA-3f7w-7j77-73m5 The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The plugin allows administrators (via its settings) to extend the ability to submit events to unauthenticated users, which would allow unauthenticated attackers to exploit this vulnerability. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-3f7v-qx94-666m DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF) | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу