Количество 353 714
Количество 353 714
GHSA-2jv5-xv66-fhx8
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.
GHSA-2jv5-wvvg-c9hj
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
GHSA-2jv5-mm7g-6r3r
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service.
GHSA-2jv5-h643-m9jp
IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
GHSA-2jv5-9r88-3w3p
python-multipart vulnerable to Content-Type Header ReDoS
GHSA-2jv5-59rp-vmgj
The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2jv5-2qvr-82qr
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
GHSA-2jv4-vc4g-7mp7
Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
GHSA-2jv4-g2j5-gcgx
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
GHSA-2jv4-86qg-m23h
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
GHSA-2jv4-596w-g9hj
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-2jv4-4qp4-gcjc
Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.
GHSA-2jv3-v37p-65w3
CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources
GHSA-2jv3-mh5v-j4w2
Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.
GHSA-2jv3-8jp8-xgcm
Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0.
GHSA-2jv2-97wr-gpc9
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
GHSA-2jrx-vp4g-6wgj
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later
GHSA-2jrx-hm6v-q9c6
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.
GHSA-2jrx-fmqr-7h3v
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.
GHSA-2jrw-c95w-h43g
Mautic has an Authorization Bypass in API v2 Endpoints
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2jv5-xv66-fhx8 A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function. | CVSS3: 4.6 | 0% Низкий | около 2 лет назад | |
GHSA-2jv5-wvvg-c9hj Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | 2% Низкий | около 4 лет назад | ||
GHSA-2jv5-mm7g-6r3r SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may impact availability of product service. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-2jv5-h643-m9jp IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token. | 1% Низкий | около 4 лет назад | ||
GHSA-2jv5-9r88-3w3p python-multipart vulnerable to Content-Type Header ReDoS | CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | |
GHSA-2jv5-59rp-vmgj The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortcode in all versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 2 лет назад | |
GHSA-2jv5-2qvr-82qr Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | CVSS3: 7.5 | 1% Низкий | 18 дней назад | |
GHSA-2jv4-vc4g-7mp7 Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service. | 0% Низкий | около 4 лет назад | ||
GHSA-2jv4-g2j5-gcgx in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. | CVSS3: 6.1 | 0% Низкий | около 1 года назад | |
GHSA-2jv4-86qg-m23h The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | CVSS3: 2.7 | 1% Низкий | больше 1 года назад | |
GHSA-2jv4-596w-g9hj In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-2jv4-4qp4-gcjc Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors. | 6% Низкий | около 4 лет назад | ||
GHSA-2jv3-v37p-65w3 CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-2jv3-mh5v-j4w2 Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop. | 0% Низкий | около 4 лет назад | ||
GHSA-2jv3-8jp8-xgcm Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design allows Stored XSS. This issue affects Contact Form 7 Material Design: from n/a through 1.0.0. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-2jv2-97wr-gpc9 AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2jrx-vp4g-6wgj A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-2jrx-hm6v-q9c6 SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected. | 3% Низкий | больше 4 лет назад | ||
GHSA-2jrx-fmqr-7h3v Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-2jrw-c95w-h43g Mautic has an Authorization Bypass in API v2 Endpoints | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу