Количество 375 356
Количество 375 356
GHSA-36g3-5c2m-mrqx
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.
GHSA-36g2-h6pw-2fpg
The “Clever Addons for Elementor� WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
GHSA-36fx-x9hq-pvcq
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.
GHSA-36fx-rf6c-vc8x
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
GHSA-36fw-cxfr-92fm
In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709
GHSA-36fw-7hg5-xv5p
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
GHSA-36fw-723j-3pvw
muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.
GHSA-36fv-g9xp-84xv
Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.
GHSA-36fv-7fxv-xr4g
Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.
GHSA-36fv-6vjc-jf92
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
GHSA-36fr-xc4j-fmhw
Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.
GHSA-36fr-w5h7-5f28
Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.
GHSA-36fr-3wg8-q5v8
Concrete CMS Cross-site Scripting vulnerability
GHSA-36fr-2gcj-778v
A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.
GHSA-36fq-jgmw-4r9c
Keras is vulnerable to Deserialization of Untrusted Data
GHSA-36fq-6c6v-89gr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.
GHSA-36fq-3276-7898
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-36fp-xj79-95mx
Links may not be rewritten according to policy in some specially formatted emails.
GHSA-36fm-v9wv-56jf
Cross-site Scripting in OpenCart
GHSA-36fm-j33w-c25f
Privilege escalation (PR)/RCE from account through class sheet
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-36g3-5c2m-mrqx In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET /v1/users/me` and `GET /v1/users/me/org` API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated. | CVSS3: 9.1 | 0% Низкий | почти 2 года назад | |
GHSA-36g2-h6pw-2fpg The “Clever Addons for Elementorâ€? WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | 1% Низкий | больше 4 лет назад | ||
GHSA-36fx-x9hq-pvcq Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. | 2% Низкий | больше 4 лет назад | ||
GHSA-36fx-rf6c-vc8x Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112. | 3% Низкий | больше 4 лет назад | ||
GHSA-36fw-cxfr-92fm In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709 | 0% Низкий | больше 4 лет назад | ||
GHSA-36fw-7hg5-xv5p A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller. | 35% Средний | больше 4 лет назад | ||
GHSA-36fw-723j-3pvw muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file. | 0% Низкий | больше 4 лет назад | ||
GHSA-36fv-g9xp-84xv Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-36fv-7fxv-xr4g Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. | 16% Средний | больше 4 лет назад | ||
GHSA-36fv-6vjc-jf92 If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup. | CVSS3: 6.7 | 1% Низкий | больше 1 года назад | |
GHSA-36fr-xc4j-fmhw Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program. | 0% Низкий | больше 4 лет назад | ||
GHSA-36fr-w5h7-5f28 Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005. | 10% Низкий | больше 4 лет назад | ||
GHSA-36fr-3wg8-q5v8 Concrete CMS Cross-site Scripting vulnerability | CVSS3: 3.5 | 1% Низкий | почти 3 года назад | |
GHSA-36fr-2gcj-778v A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-36fq-jgmw-4r9c Keras is vulnerable to Deserialization of Untrusted Data | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-36fq-6c6v-89gr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-36fq-3276-7898 A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 1% Низкий | около 2 лет назад | |
GHSA-36fp-xj79-95mx Links may not be rewritten according to policy in some specially formatted emails. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-36fm-v9wv-56jf Cross-site Scripting in OpenCart | CVSS3: 5.4 | 3% Низкий | больше 5 лет назад | |
GHSA-36fm-j33w-c25f Privilege escalation (PR)/RCE from account through class sheet | CVSS3: 9.9 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу