Количество 353 489
Количество 353 489
GHSA-29gx-388f-w262
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.
GHSA-29gw-r2hj-fm58
Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.
GHSA-29gw-9793-fvw7
IPython vulnerable to command injection via set_term_title
GHSA-29gv-cv9c-r93w
This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
GHSA-29gr-w86r-vj34
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
GHSA-29gr-w57f-rpfw
actionpack vulnerable to Path Traversal
GHSA-29gq-wq8x-vfcr
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
GHSA-29gq-rw72-mrqg
In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.
GHSA-29gq-h27w-54qf
Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text
GHSA-29gp-96hf-p856
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.
GHSA-29gp-92wp-94q8
react-dev-utils on Windows vulnerable to Remote Code Execution
GHSA-29gp-2c3m-3j6m
Sandbox Escape by math function in smarty
GHSA-29gm-gchh-5j4j
Microsoft Office Visio Remote Code Execution Vulnerability
GHSA-29gj-xrph-g435
A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.
GHSA-29gj-vxgx-8qph
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8.
GHSA-29gj-jj49-x9g7
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-29gh-89p4-ffqv
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
GHSA-29gh-3cpv-qpjp
Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.
GHSA-29gg-qvj7-46c7
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
GHSA-29gg-8679-22q3
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-29gx-388f-w262 Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list. | 2% Низкий | больше 4 лет назад | ||
GHSA-29gw-r2hj-fm58 Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device. | CVSS3: 9.6 | 1% Низкий | больше 2 лет назад | |
GHSA-29gw-9793-fvw7 IPython vulnerable to command injection via set_term_title | CVSS3: 4.5 | 1% Низкий | больше 3 лет назад | |
GHSA-29gv-cv9c-r93w This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. | CVSS3: 8.6 | 0% Низкий | 7 месяцев назад | |
GHSA-29gr-w86r-vj34 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | CVSS3: 7.3 | 0% Низкий | 17 дней назад | |
GHSA-29gr-w57f-rpfw actionpack vulnerable to Path Traversal | 3% Низкий | почти 9 лет назад | ||
GHSA-29gq-wq8x-vfcr The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-29gq-rw72-mrqg In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file. | CVSS3: 7.3 | 0% Низкий | около 2 лет назад | |
GHSA-29gq-h27w-54qf Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-29gp-96hf-p856 Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-29gp-92wp-94q8 react-dev-utils on Windows vulnerable to Remote Code Execution | 3% Низкий | больше 7 лет назад | ||
GHSA-29gp-2c3m-3j6m Sandbox Escape by math function in smarty | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-29gm-gchh-5j4j Microsoft Office Visio Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
GHSA-29gj-xrph-g435 A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'. | CVSS3: 4.4 | 3% Низкий | около 4 лет назад | |
GHSA-29gj-vxgx-8qph Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8. | CVSS3: 7.1 | 0% Низкий | 18 дней назад | |
GHSA-29gj-jj49-x9g7 Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 2% Низкий | почти 3 года назад | |
GHSA-29gh-89p4-ffqv European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-29gh-3cpv-qpjp Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection. | CVSS3: 2.3 | 4% Низкий | около 4 лет назад | |
GHSA-29gg-qvj7-46c7 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 2% Низкий | около 1 года назад | |
GHSA-29gg-8679-22q3 Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | CVSS3: 7.8 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу