Количество 374 825
Количество 374 825
GHSA-3qmm-r55x-hpxx
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
GHSA-3qmj-w8xr-h39r
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."
GHSA-3qmj-w5mh-5gv3
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.
GHSA-3qmj-rc63-mhjw
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.
GHSA-3qmj-qw66-fwx8
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap-OOB-WRITE would be triggered which could have Remote Code Execution (RCE) potential.
GHSA-3qmj-gxp7-229g
SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.
GHSA-3qmj-8cpx-9xxp
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.
GHSA-3qmh-69j2-8hj7
Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.
GHSA-3qmg-wxq2-g22p
Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.
GHSA-3qmg-c9vc-r47j
Mercurial is vulnerable to shell injection attack
GHSA-3qmg-867g-8xrq
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
GHSA-3qmf-g4j6-v744
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
GHSA-3qmf-fj65-6vmf
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
GHSA-3qmf-6344-4f7m
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).
GHSA-3qmc-vv7g-wccj
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
GHSA-3qmc-cj7q-62hv
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
GHSA-3qmc-2r76-4rqp
Redwood is vulnerable to account takeover via dbAuth "forgot-password"
GHSA-3qm9-v325-gx6g
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
GHSA-3qm9-8m3h-5r34
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541
GHSA-3qm9-52c7-2c7g
HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3qmm-r55x-hpxx Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
GHSA-3qmj-w8xr-h39r Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled." | 1% Низкий | больше 4 лет назад | ||
GHSA-3qmj-w5mh-5gv3 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function. | CVSS3: 9.8 | 6% Низкий | больше 2 лет назад | |
GHSA-3qmj-rc63-mhjw A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
GHSA-3qmj-qw66-fwx8 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out of bound (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap-OOB-WRITE would be triggered which could have Remote Code Execution (RCE) potential. | CVSS3: 9.8 | 1% Низкий | 4 месяца назад | |
GHSA-3qmj-gxp7-229g SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3qmj-8cpx-9xxp VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process. | 1% Низкий | больше 4 лет назад | ||
GHSA-3qmh-69j2-8hj7 Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields. | 2% Низкий | больше 4 лет назад | ||
GHSA-3qmg-wxq2-g22p Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload. | CVSS3: 6.1 | 1% Низкий | почти 3 года назад | |
GHSA-3qmg-c9vc-r47j Mercurial is vulnerable to shell injection attack | CVSS3: 9.8 | 6% Низкий | больше 4 лет назад | |
GHSA-3qmg-867g-8xrq During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1. | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-3qmf-g4j6-v744 The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration. | CVSS3: 7.1 | 0% Низкий | 17 дней назад | |
GHSA-3qmf-fj65-6vmf The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
GHSA-3qmf-6344-4f7m An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020). | 0% Низкий | больше 4 лет назад | ||
GHSA-3qmc-vv7g-wccj Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function. | CVSS3: 8.8 | 1% Низкий | почти 3 года назад | |
GHSA-3qmc-cj7q-62hv Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-3qmc-2r76-4rqp Redwood is vulnerable to account takeover via dbAuth "forgot-password" | CVSS3: 8.2 | почти 4 года назад | ||
GHSA-3qm9-v325-gx6g OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. | 1% Низкий | почти 5 лет назад | ||
GHSA-3qm9-8m3h-5r34 In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541 | 0% Низкий | больше 4 лет назад | ||
GHSA-3qm9-52c7-2c7g HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу