Количество 359 267
Количество 359 267
GHSA-3866-cc7f-3jx4
The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.
GHSA-3866-98fq-wg7f
The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.
GHSA-3866-72wv-xq49
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3866-5rgc-4rr9
Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.
GHSA-3865-xcmr-qxp5
In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.
GHSA-3864-rp2m-2qfj
libre-chat Path Traversal vulnerability
GHSA-3864-88qj-q5jc
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
GHSA-3863-q6pp-rrcg
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.
GHSA-3863-h4xw-2xv3
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
GHSA-3863-2447-669p
transformers has a Deserialization of Untrusted Data vulnerability
GHSA-3862-v28r-vqw4
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
GHSA-3862-j6jr-jg22
Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.
GHSA-3862-fmr3-4f3h
Broadleaf vulnerable to Cross-site Scripting
GHSA-3862-f8g9-4ffc
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.
GHSA-3862-c622-v4fp
Cross-site Scripting in Backdrop CMS
GHSA-3862-5qvv-3rvv
The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-385x-88c3-c379
Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.
GHSA-385w-hjpp-r4cx
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
GHSA-385w-3r67-h9rr
Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.
GHSA-385r-vgx4-4g7p
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3866-cc7f-3jx4 The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3866-98fq-wg7f The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it. | 2% Низкий | больше 4 лет назад | ||
GHSA-3866-72wv-xq49 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3866-5rgc-4rr9 Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button. | 1% Низкий | больше 4 лет назад | ||
GHSA-3865-xcmr-qxp5 In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599. | CVSS3: 6.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3864-rp2m-2qfj libre-chat Path Traversal vulnerability | CVSS3: 9.1 | 1% Низкий | больше 1 года назад | |
GHSA-3864-88qj-q5jc Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter. | CVSS3: 6.5 | 11% Средний | больше 1 года назад | |
GHSA-3863-q6pp-rrcg All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
GHSA-3863-h4xw-2xv3 An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c. | 7% Низкий | около 4 лет назад | ||
GHSA-3863-2447-669p transformers has a Deserialization of Untrusted Data vulnerability | CVSS3: 9 | 1% Низкий | больше 2 лет назад | |
GHSA-3862-v28r-vqw4 seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3862-j6jr-jg22 Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file. | 28% Средний | больше 4 лет назад | ||
GHSA-3862-fmr3-4f3h Broadleaf vulnerable to Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-3862-f8g9-4ffc Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-3862-c622-v4fp Cross-site Scripting in Backdrop CMS | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3862-5qvv-3rvv The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-385x-88c3-c379 Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376. | CVSS3: 6.7 | 1% Низкий | около 4 лет назад | |
GHSA-385w-hjpp-r4cx Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access. | CVSS3: 7.4 | 1% Низкий | около 3 лет назад | |
GHSA-385w-3r67-h9rr Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-385r-vgx4-4g7p Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад |
Уязвимостей на страницу