Количество 375 453
Количество 375 453
GHSA-37m6-8rw8-wh8f
HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.
GHSA-37m6-73f6-jm7w
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.
GHSA-37m6-2cm3-x5m2
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
GHSA-37m5-m4q3-fc6x
Froxlor: BIND Zone File Injection via TXT Record Content
GHSA-37m5-593h-89wf
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
GHSA-37m5-42qp-4qpr
Cross-site scripting in LocalStack
GHSA-37m4-w5jp-r3px
Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.
GHSA-37m4-hvw3-vwmc
Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2.
GHSA-37m4-hqxv-w26g
XWiki Platform CSRF remote code execution through scheduler job's document reference
GHSA-37m3-qp37-x3c6
Apache Geode gfsh query vulnerability
GHSA-37m3-29m6-vgxq
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter.
GHSA-37m2-v8vp-gx9v
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
GHSA-37m2-9j5v-c4v4
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.
GHSA-37jx-v87h-x8gc
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
GHSA-37jx-fgfr-x4xh
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.
GHSA-37jw-xgjq-3fmq
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
GHSA-37jw-9hhw-q8w8
An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.
GHSA-37jv-v9vv-wxwv
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.
GHSA-37jv-rq4h-f78r
Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.
GHSA-37jr-rxv8-wwqj
In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-37m6-8rw8-wh8f HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information. | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
GHSA-37m6-73f6-jm7w REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases. | 2% Низкий | больше 4 лет назад | ||
GHSA-37m6-2cm3-x5m2 The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-37m5-m4q3-fc6x Froxlor: BIND Zone File Injection via TXT Record Content | CVSS3: 7.6 | 0% Низкий | 4 месяца назад | |
GHSA-37m5-593h-89wf In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-37m5-42qp-4qpr Cross-site scripting in LocalStack | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
GHSA-37m4-w5jp-r3px Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-37m4-hvw3-vwmc Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through 2.7.2. | CVSS3: 6.3 | 0% Низкий | 9 месяцев назад | |
GHSA-37m4-hqxv-w26g XWiki Platform CSRF remote code execution through scheduler job's document reference | CVSS3: 9 | 1% Низкий | больше 2 лет назад | |
GHSA-37m3-qp37-x3c6 Apache Geode gfsh query vulnerability | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-37m3-29m6-vgxq PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to execute arbitrary PHP code via a URL in the inews_path parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-37m2-v8vp-gx9v Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 10 месяцев назад | |||
GHSA-37m2-9j5v-c4v4 A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow. | 2% Низкий | больше 1 года назад | ||
GHSA-37jx-v87h-x8gc Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-37jx-fgfr-x4xh Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113. | CVSS3: 7.5 | 14% Средний | больше 4 лет назад | |
GHSA-37jw-xgjq-3fmq A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-37jw-9hhw-q8w8 An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'. | 1% Низкий | больше 4 лет назад | ||
GHSA-37jv-v9vv-wxwv Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. | CVSS3: 5.1 | 0% Низкий | 4 месяца назад | |
GHSA-37jv-rq4h-f78r Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-37jr-rxv8-wwqj In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу