Количество 353 489
Количество 353 489
GHSA-2gw7-672m-m38x
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
GHSA-2gw6-v2h7-g6vm
A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.
GHSA-2gw6-73wc-x88f
Apache Geode information disclosure vulnerability
GHSA-2gw5-9px7-vp56
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
GHSA-2gw3-mxrj-jwhh
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.
GHSA-2gw2-qgjg-xh6p
Namada-apps allows Post-Genesis Validator Bypass
GHSA-2gw2-8q9w-cw8p
Ruby-ffi has a DLL loading issue
GHSA-2gvx-rx63-w97c
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.
GHSA-2gvx-cpxc-42hj
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.
GHSA-2gvx-5frj-6px5
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
GHSA-2gvx-55m9-gpjj
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored within the application.
GHSA-2gvw-w6fj-7m3c
Argo CD's API server does not enforce project sourceNamespaces
GHSA-2gvw-rh95-856r
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
GHSA-2gvw-r9m5-r3m7
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
GHSA-2gvw-95cm-ffm9
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.
GHSA-2gvv-xcmg-4m9m
OX App Suite through 7.10.2 has Incorrect Access Control.
GHSA-2gvv-fwhv-83hw
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
GHSA-2gvv-8pww-2c2x
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
GHSA-2gvv-5vxj-jrw7
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
GHSA-2gvr-pmm6-8pmw
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2gw7-672m-m38x The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-2gw6-v2h7-g6vm A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent. | 0% Низкий | больше 4 лет назад | ||
GHSA-2gw6-73wc-x88f Apache Geode information disclosure vulnerability | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-2gw5-9px7-vp56 In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118. | CVSS3: 7.4 | 1% Низкий | почти 3 года назад | |
GHSA-2gw3-mxrj-jwhh Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-2gw2-qgjg-xh6p Namada-apps allows Post-Genesis Validator Bypass | больше 1 года назад | |||
GHSA-2gw2-8q9w-cw8p Ruby-ffi has a DLL loading issue | CVSS3: 7.8 | 1% Низкий | почти 8 лет назад | |
GHSA-2gvx-rx63-w97c Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802. | 0% Низкий | около 4 лет назад | ||
GHSA-2gvx-cpxc-42hj Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-2gvx-5frj-6px5 Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-2gvx-55m9-gpjj During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored within the application. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-2gvw-w6fj-7m3c Argo CD's API server does not enforce project sourceNamespaces | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2gvw-rh95-856r Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | 0% Низкий | 2 дня назад | ||
GHSA-2gvw-r9m5-r3m7 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | около 2 лет назад | |||
GHSA-2gvw-95cm-ffm9 provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock. | 0% Низкий | около 4 лет назад | ||
GHSA-2gvv-xcmg-4m9m OX App Suite through 7.10.2 has Incorrect Access Control. | 2% Низкий | около 4 лет назад | ||
GHSA-2gvv-fwhv-83hw An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-2gvv-8pww-2c2x Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors. | 3% Низкий | около 4 лет назад | ||
GHSA-2gvv-5vxj-jrw7 A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | 2% Низкий | около 4 лет назад | ||
GHSA-2gvr-pmm6-8pmw Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051. | 17% Средний | около 4 лет назад |
Уязвимостей на страницу