Количество 353 714
Количество 353 714
GHSA-2jqm-x3hr-jjmq
SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.
GHSA-2jqj-xw9v-qv9j
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.
GHSA-2jqj-w7h9-j4g2
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
GHSA-2jqj-5qv2-xvcg
ezsystems/ezplatform-richtext allows access to external entities in XML
GHSA-2jqh-5pvj-7mrg
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
GHSA-2jqf-xvwf-cwgj
I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.
GHSA-2jqf-mvg9-fhf9
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2jqf-jwg5-2mm3
Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
GHSA-2jqf-9377-3hhp
Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.
GHSA-2jqc-m5c2-q976
The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521.
GHSA-2jqc-4vc4-2j4m
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-2jq9-6xx7-3h29
`temporary` makes use of uninitialized memory
GHSA-2jq8-xw89-gcg8
The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.
GHSA-2jq7-x2v9-98wx
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.
GHSA-2jq7-pgqq-gqqj
TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism
GHSA-2jq7-6vh9-gh84
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.
GHSA-2jq6-ffph-p4h8
Kubernetes arbitrary file overwrite
GHSA-2jq5-wq32-4rfq
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.
GHSA-2jq4-q6vv-4cp3
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
GHSA-2jq4-cxqg-p845
The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2jqm-x3hr-jjmq SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls. | CVSS3: 4.1 | 0% Низкий | 13 дней назад | |
GHSA-2jqj-xw9v-qv9j CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2jqj-w7h9-j4g2 In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2jqj-5qv2-xvcg ezsystems/ezplatform-richtext allows access to external entities in XML | больше 1 года назад | |||
GHSA-2jqh-5pvj-7mrg Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. | 1% Низкий | около 4 лет назад | ||
GHSA-2jqf-xvwf-cwgj I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect. | 1% Низкий | около 4 лет назад | ||
GHSA-2jqf-mvg9-fhf9 Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 56% Средний | больше 4 лет назад | ||
GHSA-2jqf-jwg5-2mm3 Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability." | 21% Средний | около 4 лет назад | ||
GHSA-2jqf-9377-3hhp Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2jqc-m5c2-q976 The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-2jqc-4vc4-2j4m A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 1% Низкий | больше 1 года назад | |
GHSA-2jq9-6xx7-3h29 `temporary` makes use of uninitialized memory | почти 4 года назад | |||
GHSA-2jq8-xw89-gcg8 The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer. | 5% Низкий | около 4 лет назад | ||
GHSA-2jq7-x2v9-98wx ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files. | CVSS3: 4.9 | 1% Низкий | около 3 лет назад | |
GHSA-2jq7-pgqq-gqqj TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism | 2% Низкий | около 4 лет назад | ||
GHSA-2jq7-6vh9-gh84 A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface. | CVSS3: 4.6 | 0% Низкий | 8 месяцев назад | |
GHSA-2jq6-ffph-p4h8 Kubernetes arbitrary file overwrite | CVSS3: 5.5 | 2% Низкий | около 4 лет назад | |
GHSA-2jq5-wq32-4rfq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2jq4-q6vv-4cp3 Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE | CVSS3: 9.6 | около 1 месяца назад | ||
GHSA-2jq4-cxqg-p845 The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу