Количество 375 727
Количество 375 727
GHSA-xr7x-6c7p-2fw4
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.
GHSA-xr7w-c4xp-gqc3
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
GHSA-xr7w-9r28-r57c
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
GHSA-xr7v-qwrm-67xg
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.
GHSA-xr7v-m9px-q4qj
MetaGPT has an eval injection in metagpt/strategy/tot.py
GHSA-xr7v-j379-34v9
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
GHSA-xr7v-hj32-mr4r
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
GHSA-xr7v-c623-gxm3
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
GHSA-xr7v-8xc4-62vc
ZoneMinder before 1.36.13 allows remote code execution via an invalid language.
GHSA-xr7v-8p7c-rjfh
A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.
GHSA-xr7r-f8xq-vfvv
runc vulnerable to container breakout through process.cwd trickery and leaked fds
GHSA-xr7r-88qv-q7hm
Out of bounds write in serde_cbor
GHSA-xr7r-38qp-crjh
** DISPUTED ** Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel."
GHSA-xr7r-292v-jxg8
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
GHSA-xr7r-23jq-mmmx
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
GHSA-xr7q-jx4m-x55m
Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go
GHSA-xr7q-92rc-hj9g
In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208662370
GHSA-xr7q-639h-425q
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.
GHSA-xr7q-4cmw-j44v
A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xr7p-qm7q-pc56
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xr7x-6c7p-2fw4 Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xr7w-c4xp-gqc3 A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables. | CVSS3: 6.7 | 0% Низкий | почти 3 года назад | |
GHSA-xr7w-9r28-r57c Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php. | 42% Средний | больше 4 лет назад | ||
GHSA-xr7v-qwrm-67xg In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string. | CVSS3: 9.8 | 8% Низкий | больше 4 лет назад | |
GHSA-xr7v-m9px-q4qj MetaGPT has an eval injection in metagpt/strategy/tot.py | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
GHSA-xr7v-j379-34v9 NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality | CVSS3: 4.9 | 0% Низкий | 8 месяцев назад | |
GHSA-xr7v-hj32-mr4r Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
GHSA-xr7v-c623-gxm3 Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-xr7v-8xc4-62vc ZoneMinder before 1.36.13 allows remote code execution via an invalid language. | CVSS3: 9.8 | 67% Средний | больше 4 лет назад | |
GHSA-xr7v-8p7c-rjfh A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | CVSS3: 9.8 | 1 день назад | ||
GHSA-xr7r-f8xq-vfvv runc vulnerable to container breakout through process.cwd trickery and leaked fds | CVSS3: 8.6 | 18% Средний | больше 2 лет назад | |
GHSA-xr7r-88qv-q7hm Out of bounds write in serde_cbor | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-xr7r-38qp-crjh ** DISPUTED ** Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel." | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-xr7r-292v-jxg8 The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-xr7r-23jq-mmmx A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. | CVSS3: 8.8 | 1% Низкий | почти 5 лет назад | |
GHSA-xr7q-jx4m-x55m Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go | около 2 лет назад | |||
GHSA-xr7q-92rc-hj9g In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208662370 | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xr7q-639h-425q Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
GHSA-xr7q-4cmw-j44v A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 7.3 | 1% Низкий | 6 месяцев назад | |
GHSA-xr7p-qm7q-pc56 An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent. | CVSS3: 5.5 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу