Количество 356 366
Количество 356 366
GHSA-2xwp-m7mq-7q3r
CLI does not correctly implement strict mode
GHSA-2xwp-jx33-g2fj
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
GHSA-2xwp-gm9f-mwxv
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.
GHSA-2xwp-7j3p-c78x
Cross site scripting in SiteServer CMS
GHSA-2xwp-3v4p-x875
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
GHSA-2xwm-mmjj-m5x4
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.
GHSA-2xwm-j535-wh92
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
GHSA-2xwm-fqp4-pw7f
Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.
GHSA-2xwm-f2v4-92vh
Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.
GHSA-2xwm-4h2q-ggfx
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
GHSA-2xwj-vx39-jqg9
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33.
GHSA-2xwj-vc46-67hj
Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7.
GHSA-2xwj-rw2w-xr5q
All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.
GHSA-2xwj-g27r-p9cr
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program.
GHSA-2xwj-cxrx-46h4
Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.
GHSA-2xwj-6795-v7p4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
GHSA-2xwh-g8m2-c95g
Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS.
GHSA-2xwg-c668-f9x5
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-2xwg-9gx4-w8wf
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."
GHSA-2xwg-7hvq-gvq8
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573237.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2xwp-m7mq-7q3r CLI does not correctly implement strict mode | почти 6 лет назад | |||
GHSA-2xwp-jx33-g2fj NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-2xwp-gm9f-mwxv Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-2xwp-7j3p-c78x Cross site scripting in SiteServer CMS | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-2xwp-3v4p-x875 Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwm-mmjj-m5x4 SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO. | 1% Низкий | около 4 лет назад | ||
GHSA-2xwm-j535-wh92 The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting. | CVSS3: 8.8 | 25% Средний | около 4 лет назад | |
GHSA-2xwm-fqp4-pw7f Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands. | 0% Низкий | больше 4 лет назад | ||
GHSA-2xwm-f2v4-92vh Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2xwm-4h2q-ggfx Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete | CVSS3: 5.4 | 0% Низкий | 17 дней назад | |
GHSA-2xwj-vx39-jqg9 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-2xwj-vc46-67hj Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-2xwj-rw2w-xr5q All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2xwj-g27r-p9cr An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2xwj-cxrx-46h4 Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540. | 2% Низкий | около 4 лет назад | ||
GHSA-2xwj-6795-v7p4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-2xwh-g8m2-c95g Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS. | 2% Низкий | больше 4 лет назад | ||
GHSA-2xwg-c668-f9x5 Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory. | 1% Низкий | около 4 лет назад | ||
GHSA-2xwg-9gx4-w8wf Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment." | 49% Средний | больше 4 лет назад | ||
GHSA-2xwg-7hvq-gvq8 In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573237. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу