Количество 355 704
Количество 355 704
GHSA-2wmq-wq3w-j93h
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in question.
GHSA-2wmq-9w92-6xx4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1.
GHSA-2wmq-3m94-g4jr
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651
GHSA-2wmp-7qf6-49px
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
GHSA-2wmp-6cvh-326h
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
GHSA-2wmm-vrhw-cf55
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.
GHSA-2wmm-f268-hrpm
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
GHSA-2wmm-cc27-75cj
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
GHSA-2wmm-3686-65hx
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.
GHSA-2wmj-8mqg-r9q8
Moodle has Incorrect Default Permissions
GHSA-2wmj-46rj-qm2w
ZITADEL Account Takeover via Malicious Host Header Injection
GHSA-2wmh-hj9f-qxhx
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
GHSA-2wmh-359c-rw99
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.
GHSA-2wmh-22pv-vc2h
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
GHSA-2wmg-wcpx-h559
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8.
GHSA-2wmg-qmv3-pmvc
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086.
GHSA-2wmg-q3rm-p93r
NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
GHSA-2wmg-pcgw-7mxw
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block – Display your videos as a gallery in a professional way allows Stored XSS. This issue affects Video Gallery Block – Display your videos as a gallery in a professional way: from n/a through 1.1.0.
GHSA-2wmg-hcwc-fx57
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7.
GHSA-2wmg-9g29-r2rp
The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2wmq-wq3w-j93h Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in question. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-2wmq-9w92-6xx4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-2wmq-3m94-g4jr Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that routes to an external web server. Mattermost Advisory ID: MMSA-2026-00651 | CVSS3: 6.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-2wmp-7qf6-49px Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 3 года назад | |
GHSA-2wmp-6cvh-326h Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. | CVSS3: 8.8 | 2% Низкий | больше 2 лет назад | |
GHSA-2wmm-vrhw-cf55 Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts. | 1% Низкий | больше 4 лет назад | ||
GHSA-2wmm-f268-hrpm The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | CVSS3: 8 | 1% Низкий | почти 4 года назад | |
GHSA-2wmm-cc27-75cj A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox. | CVSS3: 9.6 | 1% Низкий | почти 2 года назад | |
GHSA-2wmm-3686-65hx Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-2wmj-8mqg-r9q8 Moodle has Incorrect Default Permissions | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-2wmj-46rj-qm2w ZITADEL Account Takeover via Malicious Host Header Injection | CVSS3: 8.1 | 1% Низкий | больше 2 лет назад | |
GHSA-2wmh-hj9f-qxhx Contributor SQL Injection in WP Job Portal <= 2.5.2 versions. | CVSS3: 8.5 | 0% Низкий | около 1 месяца назад | |
GHSA-2wmh-359c-rw99 Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition. | 3% Низкий | около 4 лет назад | ||
GHSA-2wmh-22pv-vc2h browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL. | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-2wmg-wcpx-h559 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8. | CVSS3: 7.1 | 0% Низкий | почти 2 года назад | |
GHSA-2wmg-qmv3-pmvc Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-4435, CVE-2015-4438, CVE-2015-4441, CVE-2015-4445, CVE-2015-4451, CVE-2015-4452, CVE-2015-5085, and CVE-2015-5086. | 8% Низкий | около 4 лет назад | ||
GHSA-2wmg-q3rm-p93r NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
GHSA-2wmg-pcgw-7mxw Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block – Display your videos as a gallery in a professional way allows Stored XSS. This issue affects Video Gallery Block – Display your videos as a gallery in a professional way: from n/a through 1.1.0. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2wmg-hcwc-fx57 The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7. | CVSS3: 7.2 | 1% Низкий | около 4 лет назад | |
GHSA-2wmg-9g29-r2rp The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу