Количество 359 154
Количество 359 154
GHSA-37mg-65fg-9hr9
A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.
GHSA-37mg-42pw-cvp2
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
GHSA-37mc-f722-26x4
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
GHSA-37m9-g2hc-mjp2
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
GHSA-37m8-vrcv-2x3f
In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.
GHSA-37m7-xg97-7h4c
Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.
GHSA-37m7-jq3g-46vx
The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack
GHSA-37m7-669m-h8r7
Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.
GHSA-37m7-3gj6-4wrx
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-37m6-8rw8-wh8f
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.
GHSA-37m6-73f6-jm7w
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.
GHSA-37m6-2cm3-x5m2
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
GHSA-37m5-m4q3-fc6x
Froxlor: BIND Zone File Injection via TXT Record Content
GHSA-37m5-593h-89wf
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
GHSA-37m5-42qp-4qpr
Cross-site scripting in LocalStack
GHSA-37m4-w5jp-r3px
Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.
GHSA-37m4-hvw3-vwmc
Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.
GHSA-37m4-hqxv-w26g
XWiki Platform CSRF remote code execution through scheduler job's document reference
GHSA-37m3-qp37-x3c6
Apache Geode gfsh query vulnerability
GHSA-37m3-29m6-vgxq
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-37mg-65fg-9hr9 A vulnerability was found in Everywhere CMS. It has been classified as critical. Affected is an unknown function. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-37mg-42pw-cvp2 Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-37mc-f722-26x4 In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-37m9-g2hc-mjp2 A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-37m8-vrcv-2x3f In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires. | CVSS3: 4.4 | 0% Низкий | больше 1 года назад | |
GHSA-37m7-xg97-7h4c Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-37m7-jq3g-46vx The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-37m7-669m-h8r7 Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-37m7-3gj6-4wrx A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-37m6-8rw8-wh8f HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-37m6-73f6-jm7w REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases. | 2% Низкий | около 4 лет назад | ||
GHSA-37m6-2cm3-x5m2 The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php. | 2% Низкий | около 4 лет назад | ||
GHSA-37m5-m4q3-fc6x Froxlor: BIND Zone File Injection via TXT Record Content | CVSS3: 7.6 | 0% Низкий | 2 месяца назад | |
GHSA-37m5-593h-89wf In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-37m5-42qp-4qpr Cross-site scripting in LocalStack | CVSS3: 6.1 | 1% Низкий | около 5 лет назад | |
GHSA-37m4-w5jp-r3px Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-37m4-hvw3-vwmc Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2. | CVSS3: 6.3 | 0% Низкий | 7 месяцев назад | |
GHSA-37m4-hqxv-w26g XWiki Platform CSRF remote code execution through scheduler job's document reference | CVSS3: 9 | 1% Низкий | больше 2 лет назад | |
GHSA-37m3-qp37-x3c6 Apache Geode gfsh query vulnerability | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-37m3-29m6-vgxq PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу