Количество 355 558
Количество 355 558
GHSA-xr55-cjp7-wp4r
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled job to retrieve a remote .cfm file from an attacker-controlled server, which is written to the Lucee webroot and executed with the privileges of the Lucee service account. Because Lucee does not enforce integrity checks, path restrictions, or execution controls for scheduled task fetches, this feature can be abused to achieve arbitrary code execution. This issue is distinct from CVE-2024-55354.
GHSA-xr55-5xvm-9rw7
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
GHSA-xr55-38cx-p982
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
GHSA-xr54-9669-7hv5
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .
GHSA-xr53-m937-jr9c
Cross-Site Scripting in ngx-md
GHSA-xr4v-w2h4-8wmq
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions.
GHSA-xr4v-28rm-pvgw
Improper Neutralization of Special Elements used in an SQL Command Pivotal Spring Data JPA
GHSA-xr4r-mvww-q76g
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518.
GHSA-xr4r-46x6-qcpg
Windows Graphics Component Information Disclosure Vulnerability
GHSA-xr4q-6qfj-q54q
The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.
GHSA-xr4p-36qq-6m8m
Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9150, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24, Snapdragon_High_Med_2016, SXR1130
GHSA-xr4m-cp8c-xgr2
Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.
GHSA-xr4j-xq43-8mv2
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
GHSA-xr4j-2qp3-r4xc
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
GHSA-xr4h-xg4j-4v8c
Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-xr4h-93hj-62q2
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
GHSA-xr4g-wmqx-7w9w
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
GHSA-xr4g-93qp-pf58
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
GHSA-xr4f-pqj2-jwc5
Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.
GHSA-xr4f-mjxj-w6w5
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xr55-cjp7-wp4r An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled job to retrieve a remote .cfm file from an attacker-controlled server, which is written to the Lucee webroot and executed with the privileges of the Lucee service account. Because Lucee does not enforce integrity checks, path restrictions, or execution controls for scheduled task fetches, this feature can be abused to achieve arbitrary code execution. This issue is distinct from CVE-2024-55354. | 1% Низкий | около 1 года назад | ||
GHSA-xr55-5xvm-9rw7 Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected. | CVSS3: 9.8 | 11% Средний | 8 месяцев назад | |
GHSA-xr55-38cx-p982 inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | 0% Низкий | больше 4 лет назад | ||
GHSA-xr54-9669-7hv5 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution . | 17% Средний | около 4 лет назад | ||
GHSA-xr53-m937-jr9c Cross-Site Scripting in ngx-md | почти 6 лет назад | |||
GHSA-xr4v-w2h4-8wmq Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-xr4v-28rm-pvgw Improper Neutralization of Special Elements used in an SQL Command Pivotal Spring Data JPA | CVSS3: 5.6 | 1% Низкий | около 4 лет назад | |
GHSA-xr4r-mvww-q76g Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xr4r-46x6-qcpg Windows Graphics Component Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | почти 2 года назад | |
GHSA-xr4q-6qfj-q54q The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure. | 2% Низкий | около 4 лет назад | ||
GHSA-xr4p-36qq-6m8m Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9150, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24, Snapdragon_High_Med_2016, SXR1130 | 0% Низкий | около 4 лет назад | ||
GHSA-xr4m-cp8c-xgr2 Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-xr4j-xq43-8mv2 Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-xr4j-2qp3-r4xc The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xr4h-xg4j-4v8c Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
GHSA-xr4h-93hj-62q2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | почти 2 года назад | |
GHSA-xr4g-wmqx-7w9w The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-xr4g-93qp-pf58 Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory. | 0% Низкий | около 4 лет назад | ||
GHSA-xr4f-pqj2-jwc5 Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11. | 0% Низкий | больше 4 лет назад | ||
GHSA-xr4f-mjxj-w6w5 OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes | CVSS3: 8.3 | около 1 месяца назад |
Уязвимостей на страницу