Количество 353 714
Количество 353 714
GHSA-2hhw-p8mg-jrm6
Path Traversal in http-live-simulator
GHSA-2hhv-wp8q-p8vm
gri before 2.12.18 generates temporary files in an insecure way.
GHSA-2hhv-v3hc-2xgx
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.
GHSA-2hhr-r74q-p8fq
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
GHSA-2hhr-933m-5jmg
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.
GHSA-2hhq-c99x-492r
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
GHSA-2hhq-96pp-rf56
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
GHSA-2hhp-wrh5-g527
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-2hhp-r87h-qvgj
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.
GHSA-2hhp-373f-h757
Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.
GHSA-2hhm-rw5g-m2vq
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.
GHSA-2hhm-gh43-f53h
Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2hhm-535h-jfpf
In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.
GHSA-2hhh-gxpg-w8vr
The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
GHSA-2hhg-c3w2-vgr6
The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.
GHSA-2hhg-24wg-6mmv
Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.
GHSA-2hhf-q463-9hv4
Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.
GHSA-2hhf-gxff-r59q
A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.
GHSA-2hhf-9f74-3jqg
File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.
GHSA-2hhc-f86x-x74f
Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2hhw-p8mg-jrm6 Path Traversal in http-live-simulator | 3% Низкий | больше 7 лет назад | ||
GHSA-2hhv-wp8q-p8vm gri before 2.12.18 generates temporary files in an insecure way. | 1% Низкий | больше 4 лет назад | ||
GHSA-2hhv-v3hc-2xgx The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297. | CVSS3: 7.5 | 69% Средний | около 4 лет назад | |
GHSA-2hhr-r74q-p8fq The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status. | 3% Низкий | около 4 лет назад | ||
GHSA-2hhr-933m-5jmg Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-2hhq-c99x-492r ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method | CVSS3: 5.5 | 0% Низкий | около 1 месяца назад | |
GHSA-2hhq-96pp-rf56 Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76. | 2% Низкий | около 4 лет назад | ||
GHSA-2hhp-wrh5-g527 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 7 месяцев назад | |||
GHSA-2hhp-r87h-qvgj Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command. | 2% Низкий | больше 4 лет назад | ||
GHSA-2hhp-373f-h757 Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi. | 1% Низкий | больше 4 лет назад | ||
GHSA-2hhm-rw5g-m2vq The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped. | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
GHSA-2hhm-gh43-f53h Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-2hhm-535h-jfpf In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
GHSA-2hhh-gxpg-w8vr The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability." | 23% Средний | около 4 лет назад | ||
GHSA-2hhg-c3w2-vgr6 The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue. | 2% Низкий | больше 4 лет назад | ||
GHSA-2hhg-24wg-6mmv Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-2hhf-q463-9hv4 Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function. | 1% Низкий | больше 4 лет назад | ||
GHSA-2hhf-gxff-r59q A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'. | CVSS3: 6.1 | 1% Низкий | почти 3 года назад | |
GHSA-2hhf-9f74-3jqg File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2hhc-f86x-x74f Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin | CVSS3: 6.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу