Количество 375 453
Количество 375 453
GHSA-3757-h85m-r4vw
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges.
GHSA-3757-h5gm-6pj5
A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.
GHSA-3756-mp7r-crrp
Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.
GHSA-3756-hwhv-qw58
Cross site scripting in francoisjacquet/rosariosis
GHSA-3754-x86m-fj9m
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
GHSA-3754-wv73-4cjw
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-3754-c64r-8c26
The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
GHSA-3754-735c-c4rm
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
GHSA-3754-5x4h-p35m
Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.
GHSA-3753-r5q9-x6fx
A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device. This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.
GHSA-3753-m2x2-q623
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
GHSA-3753-fcfq-39h2
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
GHSA-3753-7733-qrv7
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
GHSA-3753-237w-wx4r
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
GHSA-3753-236x-jr2j
Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
GHSA-3752-8v88-868j
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.
GHSA-374x-rhrg-qpf2
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
GHSA-374x-f6v3-7m9h
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3.
GHSA-374x-c55q-x732
The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
GHSA-374w-gwqr-fmxg
brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3757-h85m-r4vw UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) vulnerability, which allows a user with write access to a directory on the system drive to execute arbitrary code with SYSTEM privileges. | CVSS3: 6.7 | 0% Низкий | 7 месяцев назад | |
GHSA-3757-h5gm-6pj5 A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. | CVSS3: 7.3 | 0% Низкий | 8 месяцев назад | |
GHSA-3756-mp7r-crrp Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file. | CVSS3: 3.3 | 0% Низкий | больше 4 лет назад | |
GHSA-3756-hwhv-qw58 Cross site scripting in francoisjacquet/rosariosis | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3754-x86m-fj9m Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977. | 6% Низкий | больше 4 лет назад | ||
GHSA-3754-wv73-4cjw Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
GHSA-3754-c64r-8c26 The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3754-735c-c4rm A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3754-5x4h-p35m Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-3753-r5q9-x6fx A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial of service (DoS) condition. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device. This vulnerability is due to improper validation of user input that is in incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-3753-m2x2-q623 File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer | CVSS3: 8.2 | 0% Низкий | 3 дня назад | |
GHSA-3753-fcfq-39h2 Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. | 0% Низкий | 6 дней назад | ||
GHSA-3753-7733-qrv7 Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests. | CVSS3: 7.2 | 1% Низкий | 11 месяцев назад | |
GHSA-3753-237w-wx4r D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability. | 1% Низкий | больше 4 лет назад | ||
GHSA-3753-236x-jr2j Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CVSS3: 9.1 | 0% Низкий | 24 дня назад | |
GHSA-3752-8v88-868j Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456. | 1% Низкий | больше 4 лет назад | ||
GHSA-374x-rhrg-qpf2 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | CVSS3: 4.4 | 0% Низкий | 12 дней назад | |
GHSA-374x-f6v3-7m9h Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.3. | CVSS3: 5.9 | 0% Низкий | больше 2 лет назад | |
GHSA-374x-c55q-x732 The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-374w-gwqr-fmxg brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу