Количество 353 489
Количество 353 489
GHSA-2924-xwpv-8gcj
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.
GHSA-2924-mp4r-x286
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
GHSA-2924-9cv7-3gpq
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.
GHSA-2924-22w3-7pm7
Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091.
GHSA-2923-vx22-37wp
Memory corruption while passing pages to DSP with an unaligned starting address.
GHSA-2923-cx8w-xvxh
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.
GHSA-28xx-pppm-vqff
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
GHSA-28xx-8j99-m32j
Malicious Package in nginxbeautifier
GHSA-28xx-6gh9-8gp4
A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
GHSA-28xx-46x6-h92x
A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611.
GHSA-28xw-m7jp-89ch
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
GHSA-28xv-ph75-77wh
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
GHSA-28xv-h724-wvrh
The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
GHSA-28xv-77rw-c8pr
NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy.
GHSA-28xr-x3rf-rhgr
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
GHSA-28xr-rgjv-2mgp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA-28xr-mwxg-3qc8
Command injection in simple-git
GHSA-28xq-f23c-p68m
Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1.
GHSA-28xq-93rr-jp78
EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance.
GHSA-28xp-g7f6-7mhf
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2924-xwpv-8gcj IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-2924-mp4r-x286 The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2924-9cv7-3gpq An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges. | 1% Низкий | около 4 лет назад | ||
GHSA-2924-22w3-7pm7 Unspecified vulnerability in HP Universal CMDB 10.01 and 10.10 allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors, aka ZDI-CAN-2091. | 8% Низкий | около 4 лет назад | ||
GHSA-2923-vx22-37wp Memory corruption while passing pages to DSP with an unaligned starting address. | CVSS3: 7.8 | 0% Низкий | 7 месяцев назад | |
GHSA-2923-cx8w-xvxh Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request. | 2% Низкий | около 4 лет назад | ||
GHSA-28xx-pppm-vqff ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction | 3 месяца назад | |||
GHSA-28xx-8j99-m32j Malicious Package in nginxbeautifier | CVSS3: 9.8 | почти 6 лет назад | ||
GHSA-28xx-6gh9-8gp4 A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | 5% Низкий | около 4 лет назад | ||
GHSA-28xx-46x6-h92x A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipulation of the argument Name/Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250611. | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-28xw-m7jp-89ch sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-28xv-ph75-77wh Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ | CVSS3: 3.7 | 0% Низкий | 17 дней назад | |
GHSA-28xv-h724-wvrh The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-28xv-77rw-c8pr NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to retrieve sensitive data via the web proxy. | 1% Низкий | около 4 лет назад | ||
GHSA-28xr-x3rf-rhgr A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. | 1% Низкий | около 4 лет назад | ||
GHSA-28xr-rgjv-2mgp Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 4.9 | 43% Средний | больше 3 лет назад | |
GHSA-28xr-mwxg-3qc8 Command injection in simple-git | CVSS3: 8.1 | 4% Низкий | больше 4 лет назад | |
GHSA-28xq-f23c-p68m Missing Authorization vulnerability in ChoPlugins Custom PC Builder Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through 1.0.1. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-28xq-93rr-jp78 EMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary commands by leveraging access to a different NetWorker instance. | CVSS3: 9.8 | 8% Низкий | около 4 лет назад | |
GHSA-28xp-g7f6-7mhf Syncthing vulnerable to symlink traversal and arbitrary file overwrite | CVSS3: 7.5 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу