Количество 353 489
Количество 353 489
GHSA-2j53-64jx-6w47
Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
GHSA-2j53-2c28-g9v2
Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement
GHSA-2j52-jv7p-x34h
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.
GHSA-2j4x-8g92-58rm
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-2j4w-p7qh-8g4g
Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.
GHSA-2j4w-p5m4-8q93
Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.
GHSA-2j4v-jvmw-mq8v
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
GHSA-2j4r-v4xj-p2f4
Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.
GHSA-2j4r-j436-59p3
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
GHSA-2j4q-9fff-236j
Apache Struts XSS Vulnerability
GHSA-2j4p-5xx5-582x
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.
GHSA-2j4p-2hc9-62f4
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
GHSA-2j4j-cgfm-hpg2
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
GHSA-2j4h-qfp4-82q7
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
GHSA-2j4h-p58q-g7mp
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
GHSA-2j4h-mgwq-9x58
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.
GHSA-2j4h-cjgh-659v
Reflected XSS vulnerability in Jenkins VncViewer Plugin
GHSA-2j4h-89r3-h3f3
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
GHSA-2j4h-4639-xjfj
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.
GHSA-2j4g-v4fv-rhwg
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2j53-64jx-6w47 Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table. | 1% Низкий | около 4 лет назад | ||
GHSA-2j53-2c28-g9v2 Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement | CVSS3: 6.5 | 4 месяца назад | ||
GHSA-2j52-jv7p-x34h Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action. | 3% Низкий | около 4 лет назад | ||
GHSA-2j4x-8g92-58rm Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 7 месяцев назад | |||
GHSA-2j4w-p7qh-8g4g Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-2j4w-p5m4-8q93 Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2j4v-jvmw-mq8v IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071. | 1% Низкий | около 4 лет назад | ||
GHSA-2j4r-v4xj-p2f4 Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-2j4r-j436-59p3 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. | CVSS3: 7.1 | 3% Низкий | около 4 лет назад | |
GHSA-2j4q-9fff-236j Apache Struts XSS Vulnerability | CVSS3: 6.1 | 8% Низкий | около 4 лет назад | |
GHSA-2j4p-5xx5-582x IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342. | 1% Низкий | около 4 лет назад | ||
GHSA-2j4p-2hc9-62f4 Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2j4j-cgfm-hpg2 SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2j4h-qfp4-82q7 Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7. | 80% Высокий | около 4 лет назад | ||
GHSA-2j4h-p58q-g7mp Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417. | 1% Низкий | около 4 лет назад | ||
GHSA-2j4h-mgwq-9x58 The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization. | 10% Низкий | около 4 лет назад | ||
GHSA-2j4h-cjgh-659v Reflected XSS vulnerability in Jenkins VncViewer Plugin | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2j4h-89r3-h3f3 The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | 2% Низкий | больше 4 лет назад | ||
GHSA-2j4h-4639-xjfj Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-2j4g-v4fv-rhwg Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability | CVSS3: 7.2 | 53% Средний | больше 2 лет назад |
Уязвимостей на страницу