Количество 353 489
Количество 353 489
GHSA-29p4-j6wv-3g22
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.
GHSA-29p4-76cr-8wvw
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from its sanitization whitelist, combined with an overly permissive wp_kses() filter at output time that allows onclick attributes on anchor tags. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the lead entries in the WordPress dashboard.
GHSA-29p4-5443-x453
Any Editor could delete any snapshot, even if they have no access to read or write them.
GHSA-29p3-gxfx-6jvv
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
GHSA-29p3-gqrh-c7mr
The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.
GHSA-29p2-vxjx-v5jw
Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.
GHSA-29p2-p4jq-qf4p
An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.
GHSA-29p2-mh35-x8wh
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
GHSA-29p2-7jvf-2jvf
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-29mx-mxf7-74q4
Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.
GHSA-29mx-jm4m-v9x5
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability.
GHSA-29mx-gmwr-vhpf
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."
GHSA-29mx-8r38-hfxq
** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
GHSA-29mx-4gvm-rgfp
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.
GHSA-29mw-wpgm-hmr9
Regular Expression Denial of Service (ReDoS) in lodash
GHSA-29mw-v354-5gg5
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
GHSA-29mw-f55p-xcww
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details.
GHSA-29mv-jj69-j88c
Rejected reason: Not used
GHSA-29mv-gccw-23pv
The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.
GHSA-29mr-mxx6-f3f5
SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-29p4-j6wv-3g22 Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode. | 0% Низкий | больше 4 лет назад | ||
GHSA-29p4-76cr-8wvw The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from its sanitization whitelist, combined with an overly permissive wp_kses() filter at output time that allows onclick attributes on anchor tags. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the lead entries in the WordPress dashboard. | CVSS3: 7.2 | 0% Низкий | 5 месяцев назад | |
GHSA-29p4-5443-x453 Any Editor could delete any snapshot, even if they have no access to read or write them. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-29p3-gxfx-6jvv CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access. | 2% Низкий | около 4 лет назад | ||
GHSA-29p3-gqrh-c7mr The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets. | 0% Низкий | около 4 лет назад | ||
GHSA-29p2-vxjx-v5jw Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10. | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
GHSA-29p2-p4jq-qf4p An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image. | CVSS3: 5.5 | 2% Низкий | около 4 лет назад | |
GHSA-29p2-mh35-x8wh Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app. | 1% Низкий | около 4 лет назад | ||
GHSA-29p2-7jvf-2jvf Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | больше 2 лет назад | ||
GHSA-29mx-mxf7-74q4 Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
GHSA-29mx-jm4m-v9x5 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-29mx-gmwr-vhpf Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX." | 1% Низкий | около 4 лет назад | ||
GHSA-29mx-8r38-hfxq ** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-29mx-4gvm-rgfp Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-29mw-wpgm-hmr9 Regular Expression Denial of Service (ReDoS) in lodash | CVSS3: 5.3 | 7% Низкий | больше 4 лет назад | |
GHSA-29mw-v354-5gg5 A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | CVSS3: 7.3 | 0% Низкий | 3 месяца назад | |
GHSA-29mw-f55p-xcww Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-29mv-jj69-j88c Rejected reason: Not used | 7 месяцев назад | |||
GHSA-29mv-gccw-23pv The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI. | CVSS3: 9.8 | 69% Средний | около 4 лет назад | |
GHSA-29mr-mxx6-f3f5 SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу