Количество 353 269
Количество 353 269
GHSA-2497-vx3h-24wc
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
GHSA-2497-mh3q-frq7
Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.
GHSA-2497-m587-h6c8
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-2497-gp99-2m74
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered
GHSA-2497-6pwj-pwg7
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
GHSA-2495-6v7r-rmx4
Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.
GHSA-2494-q7mq-75f7
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.
GHSA-2493-x4rf-23h9
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
GHSA-2493-frc2-g6pr
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.
GHSA-2493-c7mq-cpj4
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
GHSA-2493-92j5-5vh6
A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
GHSA-2493-8gg5-974x
Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889.
GHSA-2493-7x32-c5p8
Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660
GHSA-2492-xxqf-6h78
Cross Site Request Forgery in SwiftyEdit
GHSA-2492-95q9-ghpv
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.
GHSA-248x-4c3j-hcg7
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
GHSA-248v-wwj6-r5j3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.
GHSA-248v-73qf-wh7x
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.
GHSA-248v-346w-9cwc
Certifi removes GLOBALTRUST root certificate
GHSA-248r-f975-ppfj
Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2497-vx3h-24wc A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter. | 15% Средний | около 4 лет назад | ||
GHSA-2497-mh3q-frq7 Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL. | 3% Низкий | больше 4 лет назад | ||
GHSA-2497-m587-h6c8 A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | почти 2 года назад | |
GHSA-2497-gp99-2m74 Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-2497-6pwj-pwg7 Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
GHSA-2495-6v7r-rmx4 Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter. | 4% Низкий | около 4 лет назад | ||
GHSA-2494-q7mq-75f7 PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges. | 2% Низкий | больше 4 лет назад | ||
GHSA-2493-x4rf-23h9 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. | 1% Низкий | около 4 лет назад | ||
GHSA-2493-frc2-g6pr FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction. | CVSS3: 9.8 | 2% Низкий | 12 месяцев назад | |
GHSA-2493-c7mq-cpj4 The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-2493-92j5-5vh6 A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | CVSS3: 6.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-2493-8gg5-974x Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-2493-7x32-c5p8 Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660 | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-2492-xxqf-6h78 Cross Site Request Forgery in SwiftyEdit | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2492-95q9-ghpv IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-248x-4c3j-hcg7 Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file". | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
GHSA-248v-wwj6-r5j3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-248v-73qf-wh7x A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions. | 2% Низкий | больше 4 лет назад | ||
GHSA-248v-346w-9cwc Certifi removes GLOBALTRUST root certificate | 1% Низкий | около 2 лет назад | ||
GHSA-248r-f975-ppfj Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу