Количество 353 290
Количество 353 290
GHSA-2fcr-jfvc-vgg2
Gitea: Two SSRF findings
GHSA-2fcq-6m38-v4mx
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.
GHSA-2fcq-5g6c-rqrj
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA-2fcp-wr9w-5jjr
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
GHSA-2fcj-xjq4-c3h8
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later
GHSA-2fcj-pq3f-v8fp
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.
GHSA-2fcj-g7j8-pg57
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
GHSA-2fch-jvg5-crf6
Improper Input Validation python-gnupg
GHSA-2fch-hv74-fgw9
Cross site scripting (XSS) in wwbn/avideo
GHSA-2fch-5g6g-5j6q
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
GHSA-2fch-4j3w-44mf
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
GHSA-2fcg-hwv9-g767
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.
GHSA-2fcg-5wrc-pm23
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.
GHSA-2fcg-48pf-99vm
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.
GHSA-2fcc-jc2g-q7h3
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
GHSA-2fcc-j9wr-vcj4
The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
GHSA-2fcc-frh3-hm3c
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery allows Stored XSS. This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through 1.1.7.
GHSA-2fcc-cgw7-6rrw
grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device().
GHSA-2fc9-xpp8-2g9h
`@backstage/backend-common` vulnerable to path traversal through symlinks
GHSA-2fc8-wj99-h595
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2fcr-jfvc-vgg2 Gitea: Two SSRF findings | CVSS3: 7.7 | 10 дней назад | ||
GHSA-2fcq-6m38-v4mx Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069. | 7% Низкий | около 4 лет назад | ||
GHSA-2fcq-5g6c-rqrj Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 5% Низкий | около 4 лет назад | ||
GHSA-2fcp-wr9w-5jjr An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-2fcj-xjq4-c3h8 An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later | 0% Низкий | 11 месяцев назад | ||
GHSA-2fcj-pq3f-v8fp Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-2fcj-g7j8-pg57 IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-2fch-jvg5-crf6 Improper Input Validation python-gnupg | CVSS3: 7.5 | 9% Низкий | больше 7 лет назад | |
GHSA-2fch-hv74-fgw9 Cross site scripting (XSS) in wwbn/avideo | больше 3 лет назад | |||
GHSA-2fch-5g6g-5j6q Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-2fch-4j3w-44mf cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561). | 1% Низкий | около 4 лет назад | ||
GHSA-2fcg-hwv9-g767 A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-2fcg-5wrc-pm23 Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors. | 4% Низкий | около 4 лет назад | ||
GHSA-2fcg-48pf-99vm Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template. | 2% Низкий | больше 4 лет назад | ||
GHSA-2fcc-jc2g-q7h3 A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system. | CVSS3: 7.7 | 1% Низкий | больше 1 года назад | |
GHSA-2fcc-j9wr-vcj4 The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-2fcc-frh3-hm3c Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery allows Stored XSS. This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through 1.1.7. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-2fcc-cgw7-6rrw grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). | CVSS3: 5.4 | 1% Низкий | 6 месяцев назад | |
GHSA-2fc9-xpp8-2g9h `@backstage/backend-common` vulnerable to path traversal through symlinks | CVSS3: 8.7 | 1% Низкий | больше 2 лет назад | |
GHSA-2fc8-wj99-h595 Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу