Количество 355 704
Количество 355 704
GHSA-2x38-7mv7-h86v
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
GHSA-2x38-48vp-w23x
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
GHSA-2x37-xp38-hq9m
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.
GHSA-2x37-ffq7-5322
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
GHSA-2x36-vr7v-9hpm
Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.
GHSA-2x36-qhx3-7m5f
ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select
GHSA-2x36-7xfm-pgm7
Moodle default permissions too permissive
GHSA-2x35-j3p2-5qfh
A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1).
GHSA-2x35-3fw4-9jr4
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-2x35-3575-64cp
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
GHSA-2x34-p5xr-4cq8
User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.
GHSA-2x34-7fj8-wmcv
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.
GHSA-2x34-356c-v9qp
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
GHSA-2x33-pfvq-675c
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
GHSA-2x32-mwgm-xpr7
Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
GHSA-2x32-jv72-rchp
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2.
GHSA-2x32-jm95-2cpx
Authentication Bypass in dex
GHSA-2x32-fffh-53mr
KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h.
GHSA-2x32-727m-44f2
Denial of service in Linux 2.2.0 running the ldd command on a core file.
GHSA-2x32-6qfg-28pg
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeField property of a app object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6849.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2x38-7mv7-h86v A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior) | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-2x38-48vp-w23x An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices. | CVSS3: 9.8 | 86% Высокий | 7 месяцев назад | |
GHSA-2x37-xp38-hq9m A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2x37-ffq7-5322 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-2x36-vr7v-9hpm Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | почти 3 года назад | |
GHSA-2x36-qhx3-7m5f ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select | CVSS3: 9.8 | около 2 лет назад | ||
GHSA-2x36-7xfm-pgm7 Moodle default permissions too permissive | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-2x35-j3p2-5qfh A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1). | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2x35-3fw4-9jr4 n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion | 19 дней назад | |||
GHSA-2x35-3575-64cp Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-2x34-p5xr-4cq8 User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames. | CVSS3: 5.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2x34-7fj8-wmcv Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072. | CVSS3: 8.8 | 22% Средний | около 4 лет назад | |
GHSA-2x34-356c-v9qp TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-2x33-pfvq-675c The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-2x32-mwgm-xpr7 Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | CVSS3: 7.5 | 20% Средний | около 4 лет назад | |
GHSA-2x32-jv72-rchp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2x32-jm95-2cpx Authentication Bypass in dex | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-2x32-fffh-53mr KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-2x32-727m-44f2 Denial of service in Linux 2.2.0 running the ldd command on a core file. | 1% Низкий | больше 4 лет назад | ||
GHSA-2x32-6qfg-28pg This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeField property of a app object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6849. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу