Количество 353 269
Количество 353 269
GHSA-27vr-8fpq-79vm
A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.
GHSA-27vr-69mf-gx49
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.
GHSA-27vr-5h5p-w59c
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.
GHSA-27vr-24cc-98h4
Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.
GHSA-27vq-rfj8-6mx2
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-27vq-mhjm-v9gc
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
GHSA-27vq-hv74-7cqp
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
GHSA-27vq-c7q6-wxpx
NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
GHSA-27vp-6288-jjwg
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page
GHSA-27vp-2mmc-vmh3
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
GHSA-27vm-9gw5-232w
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
GHSA-27vm-5vpj-rp5g
Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel
GHSA-27vh-hwmj-r5gc
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.
GHSA-27vh-h6mc-q6g8
btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality
GHSA-27vh-g9xh-6mc8
In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections.
GHSA-27vh-g29g-4cf7
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.
GHSA-27vg-xj68-r4p8
An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.
GHSA-27vg-v28w-gqgh
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.
GHSA-27vg-qjpq-w479
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-27vg-mg2m-7qv2
In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27vr-8fpq-79vm A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-27vr-69mf-gx49 Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-27vr-5h5p-w59c Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
GHSA-27vr-24cc-98h4 Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list. | CVSS3: 6.2 | 0% Низкий | больше 2 лет назад | |
GHSA-27vq-rfj8-6mx2 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-27vq-mhjm-v9gc Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-27vq-hv74-7cqp SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type | больше 1 года назад | |||
GHSA-27vq-c7q6-wxpx NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | 0% Низкий | больше 4 лет назад | ||
GHSA-27vp-6288-jjwg The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-27vp-2mmc-vmh3 nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-27vm-9gw5-232w Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location." | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-27vm-5vpj-rp5g Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel | CVSS3: 8.2 | 1% Низкий | 3 месяца назад | |
GHSA-27vh-hwmj-r5gc Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks. | CVSS3: 9.1 | 4% Низкий | около 4 лет назад | |
GHSA-27vh-h6mc-q6g8 btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality | CVSS3: 7.4 | 1% Низкий | почти 2 года назад | |
GHSA-27vh-g9xh-6mc8 In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections. | CVSS3: 7.4 | 1% Низкий | около 4 лет назад | |
GHSA-27vh-g29g-4cf7 The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption. | CVSS3: 8.8 | 1% Низкий | около 1 года назад | |
GHSA-27vg-xj68-r4p8 An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability. | CVSS3: 7.8 | 2% Низкий | около 4 лет назад | |
GHSA-27vg-v28w-gqgh A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application. | CVSS3: 9.3 | 2% Низкий | около 4 лет назад | |
GHSA-27vg-qjpq-w479 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-27vg-mg2m-7qv2 In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу