Количество 373 892
Количество 373 892
GHSA-3p87-w3c5-27gf
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
GHSA-3p87-gqw8-4pf2
Showdoc CSRF Vulnerability
GHSA-3p87-8mrf-82ww
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
GHSA-3p87-695w-wwch
Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutab...
GHSA-3p86-xgrq-m6p6
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
GHSA-3p86-rw86-vj98
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
GHSA-3p86-mc6x-347c
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
GHSA-3p86-c4c4-99r5
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
GHSA-3p86-9fpc-5qvc
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
GHSA-3p86-9955-h393
Arbitrary File Overwrite in Eclipse JGit
GHSA-3p85-p4qg-hcrp
pimcore is vulnerable to Cross-site Scripting
GHSA-3p85-82gq-6c7j
Tanium addressed an information disclosure vulnerability in Discover.
GHSA-3p85-44fv-28jc
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
GHSA-3p84-8c6q-j555
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
GHSA-3p82-g7cx-7qrf
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-3p82-57h4-gc59
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
GHSA-3p7x-pg2q-x6w8
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.
GHSA-3p7x-m58j-fm72
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).
GHSA-3p7x-94q9-jq9x
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
GHSA-3p7w-fr8h-8fxc
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3p87-w3c5-27gf phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save | 1% Низкий | больше 4 лет назад | ||
GHSA-3p87-gqw8-4pf2 Showdoc CSRF Vulnerability | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
GHSA-3p87-8mrf-82ww In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands. They could bypass these safeguards on the “/services/streams/search“ endpoint through its “q“ parameter by circumventing endpoint restrictions using character encoding in the REST path. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will. | CVSS3: 3.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3p87-695w-wwch Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutab... | CVSS3: 5.4 | 0% Низкий | 8 дней назад | |
GHSA-3p86-xgrq-m6p6 Improper Neutralization of Input During Web Page Generation in Apache Tomcat | 10% Средний | больше 4 лет назад | ||
GHSA-3p86-rw86-vj98 Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | CVSS3: 4.3 | 1% Низкий | 3 месяца назад | |
GHSA-3p86-mc6x-347c An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-3p86-c4c4-99r5 A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-3p86-9fpc-5qvc WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1. | 4% Низкий | больше 4 лет назад | ||
GHSA-3p86-9955-h393 Arbitrary File Overwrite in Eclipse JGit | CVSS3: 8.8 | 2% Низкий | почти 3 года назад | |
GHSA-3p85-p4qg-hcrp pimcore is vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | почти 5 лет назад | |
GHSA-3p85-82gq-6c7j Tanium addressed an information disclosure vulnerability in Discover. | CVSS3: 6.5 | 1 день назад | ||
GHSA-3p85-44fv-28jc Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-3p84-8c6q-j555 In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. | CVSS3: 7.1 | 0% Низкий | 13 дней назад | |
GHSA-3p82-g7cx-7qrf A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/subcategory.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-3p82-57h4-gc59 ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions. | CVSS3: 8.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3p7x-pg2q-x6w8 The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import. | CVSS3: 9 | 1% Низкий | больше 4 лет назад | |
GHSA-3p7x-m58j-fm72 Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML). | 1% Низкий | больше 4 лет назад | ||
GHSA-3p7x-94q9-jq9x pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability | CVSS3: 7.4 | 0% Низкий | 7 месяцев назад | |
GHSA-3p7w-fr8h-8fxc The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу