Количество 354 225
Количество 354 225
GHSA-2pvr-f889-xjvm
Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.
GHSA-2pvr-5mpx-gwv9
The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject arbitrary pages and malicious web scripts.
GHSA-2pvq-xmrh-grxp
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.
GHSA-2pvq-77pm-76c4
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
GHSA-2pvp-px52-q92c
Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.
GHSA-2pvm-v53r-33rw
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
GHSA-2pvm-p3x6-gxvp
An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM.
GHSA-2pvj-w2cg-rgwq
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005af2."
GHSA-2pvj-p485-cp3m
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
GHSA-2pvj-859q-4v5p
Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
GHSA-2pvj-5j7v-jjxj
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.
GHSA-2pvh-xf99-r989
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.
GHSA-2pvh-rqjq-h9px
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
GHSA-2pvh-447j-v7m6
In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup. Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.
GHSA-2pvg-pmc4-vr2x
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.
GHSA-2pvg-g56g-vcf2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
GHSA-2pvg-9372-g3rh
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. If you want to get the best quality for vulnerability data then you always have to consider VulDB.
GHSA-2pvg-4x8f-qx36
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.
GHSA-2pvf-rfmw-cwjg
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.
GHSA-2pvf-hwww-4v9q
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2pvr-f889-xjvm Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges. | 0% Низкий | больше 4 лет назад | ||
GHSA-2pvr-5mpx-gwv9 The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject arbitrary pages and malicious web scripts. | CVSS3: 7.2 | 0% Низкий | около 2 лет назад | |
GHSA-2pvq-xmrh-grxp A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments. | CVSS3: 6.7 | 5% Низкий | около 4 лет назад | |
GHSA-2pvq-77pm-76c4 An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-2pvp-px52-q92c Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory. | 1% Низкий | около 4 лет назад | ||
GHSA-2pvm-v53r-33rw Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-2pvm-p3x6-gxvp An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-2pvj-w2cg-rgwq STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005af2." | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-2pvj-p485-cp3m matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-2pvj-859q-4v5p Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code. | 5% Низкий | около 4 лет назад | ||
GHSA-2pvj-5j7v-jjxj Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2pvh-xf99-r989 In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2pvh-rqjq-h9px naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-2pvh-447j-v7m6 In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup. Calling spi_controller_put() again in meson_spicc_remove() causes a double-put. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-2pvg-pmc4-vr2x Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-2pvg-g56g-vcf2 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-2pvg-9372-g3rh A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. If you want to get the best quality for vulnerability data then you always have to consider VulDB. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-2pvg-4x8f-qx36 kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | 1% Низкий | больше 4 лет назад | ||
GHSA-2pvf-rfmw-cwjg TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function. | CVSS3: 9.8 | 2% Низкий | 10 месяцев назад | |
GHSA-2pvf-hwww-4v9q SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу