Количество 353 489
Количество 353 489
GHSA-297g-gfvh-fg6g
Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.
GHSA-297g-cjpm-qw2x
Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.
GHSA-297g-9xq6-v8vj
Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.
GHSA-297g-9658-43jh
Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
GHSA-297g-672r-7mgh
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
GHSA-297g-44c7-436q
Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.
GHSA-297f-r9w7-w492
Magento Improper input validation vulnerability
GHSA-297f-24c2-wwfv
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
GHSA-297c-p9xm-3rhf
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.
GHSA-297c-8rmr-xrxf
Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.
GHSA-297c-34f3-r565
feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.
GHSA-2979-3fv7-8r3w
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.
GHSA-2978-89p5-cxgh
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.
GHSA-2978-6549-pf4r
SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.
GHSA-2977-w3fj-rc33
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
GHSA-2977-ph22-g7f6
The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-2977-c3c9-wqxf
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.
GHSA-2977-6mrh-4c63
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
GHSA-2977-5php-6789
Erxes Path Traversal vulnerability
GHSA-2976-mg74-v97h
Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-297g-gfvh-fg6g Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19. | CVSS3: 4.7 | 0% Низкий | 8 месяцев назад | |
GHSA-297g-cjpm-qw2x Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-297g-9xq6-v8vj Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-297g-9658-43jh Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213. | 2% Низкий | около 4 лет назад | ||
GHSA-297g-672r-7mgh Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-297g-44c7-436q Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user. | 10% Средний | больше 4 лет назад | ||
GHSA-297f-r9w7-w492 Magento Improper input validation vulnerability | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-297f-24c2-wwfv Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-297c-p9xm-3rhf A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-297c-8rmr-xrxf Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs. | 0% Низкий | около 4 лет назад | ||
GHSA-297c-34f3-r565 feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php. | 2% Низкий | около 4 лет назад | ||
GHSA-2979-3fv7-8r3w In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-2978-89p5-cxgh An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-2978-6549-pf4r SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter. | 1% Низкий | около 4 лет назад | ||
GHSA-2977-w3fj-rc33 Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2977-ph22-g7f6 The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | около 4 лет назад | ||
GHSA-2977-c3c9-wqxf Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information. | 1% Низкий | около 4 лет назад | ||
GHSA-2977-6mrh-4c63 MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-2977-5php-6789 Erxes Path Traversal vulnerability | 0% Низкий | около 1 года назад | ||
GHSA-2976-mg74-v97h Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу