Количество 353 489
Количество 353 489
GHSA-2hw6-4rv9-82fp
Uvdesk remote code execution vulnerability
GHSA-2hw5-wx32-97v6
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.
GHSA-2hw5-388c-g7xj
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
GHSA-2hw3-wmq2-hxf7
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
GHSA-2hw3-rfjc-q8m6
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.
GHSA-2hw3-h8qx-hqqp
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
GHSA-2hw3-28v7-q78p
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
GHSA-2hw2-hc6g-cv7v
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
GHSA-2hw2-h3mf-c2j9
Moodle open redirect vulnerability
GHSA-2hw2-7jq8-w9vp
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
GHSA-2hw2-62cp-p9p7
Access control bypass in Apache ZooKeeper
GHSA-2hw2-5mr3-w7wm
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
GHSA-2hvx-m86j-h9m3
Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.
GHSA-2hvx-9r8j-qvph
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-2hvx-93c2-p928
** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.
GHSA-2hvw-r4rp-mjpp
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
GHSA-2hvv-h4pw-wcm2
The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
GHSA-2hvr-h6gw-qrxp
Cargo extracting malicious crates can fill the file system
GHSA-2hvr-43xf-39rx
Not used in 2022
GHSA-2hvq-vmfm-c497
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2hw6-4rv9-82fp Uvdesk remote code execution vulnerability | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-2hw5-wx32-97v6 Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page. | 2% Низкий | около 4 лет назад | ||
GHSA-2hw5-388c-g7xj Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-2hw3-wmq2-hxf7 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-2hw3-rfjc-q8m6 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4. | CVSS3: 9 | 1% Низкий | 10 месяцев назад | |
GHSA-2hw3-h8qx-hqqp OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2hw3-28v7-q78p Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability." | 17% Средний | около 4 лет назад | ||
GHSA-2hw2-hc6g-cv7v IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application. | CVSS3: 9.8 | 1% Низкий | 9 месяцев назад | |
GHSA-2hw2-h3mf-c2j9 Moodle open redirect vulnerability | CVSS3: 7.4 | 2% Низкий | около 4 лет назад | |
GHSA-2hw2-7jq8-w9vp The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | 8% Низкий | больше 4 лет назад | ||
GHSA-2hw2-62cp-p9p7 Access control bypass in Apache ZooKeeper | CVSS3: 5.9 | 10% Низкий | около 7 лет назад | |
GHSA-2hw2-5mr3-w7wm A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | CVSS3: 6.2 | 0% Низкий | 30 дней назад | |
GHSA-2hvx-m86j-h9m3 Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function. | 3% Низкий | около 4 лет назад | ||
GHSA-2hvx-9r8j-qvph The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-2hvx-93c2-p928 ** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity. | CVSS3: 8.6 | 0% Низкий | почти 3 года назад | |
GHSA-2hvw-r4rp-mjpp Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. | CVSS3: 5.9 | 1% Низкий | почти 3 года назад | |
GHSA-2hvv-h4pw-wcm2 The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands. | 0% Низкий | около 4 лет назад | ||
GHSA-2hvr-h6gw-qrxp Cargo extracting malicious crates can fill the file system | CVSS3: 4.2 | 1% Низкий | почти 4 года назад | |
GHSA-2hvr-43xf-39rx Not used in 2022 | больше 3 лет назад | |||
GHSA-2hvq-vmfm-c497 A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу