Количество 375 268
Количество 375 268
GHSA-35jp-8cgg-p4wj
Shopware vulnerable to Server Side Template Injection in Twig using Context functions
GHSA-35jp-44cx-hw36
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.
GHSA-35jm-rm2f-hpgj
Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules.
GHSA-35jm-qwg4-c8wj
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.
GHSA-35jj-wx47-4w8r
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
GHSA-35jj-vqcf-f2jf
Hidden fields can be leaked on readable collections in Payload
GHSA-35jj-h5xp-mhvc
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.
GHSA-35jj-9635-2vjm
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.
GHSA-35jj-42hp-8gmq
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
GHSA-35jh-r3h4-6jhm
Command Injection in lodash
GHSA-35jh-p5wf-6gg4
Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.
GHSA-35jh-g8qg-jgf5
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
GHSA-35jh-78c5-6rfj
IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.
GHSA-35jh-65jp-wj73
Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).
GHSA-35jh-2r79-5r66
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
GHSA-35jg-8pwm-5q3v
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
GHSA-35jf-jfrv-9p25
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
GHSA-35jf-fw8j-m7v3
Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.
GHSA-35jc-cjp6-54c4
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
GHSA-35jc-5h4r-p9cg
Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-35jp-8cgg-p4wj Shopware vulnerable to Server Side Template Injection in Twig using Context functions | CVSS3: 8.3 | 1% Низкий | около 2 лет назад | |
GHSA-35jp-44cx-hw36 In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-35jm-rm2f-hpgj Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to ` to bypass the private IP range and blocked hostname checks in `is_private_ip()`, reaching services bound to IPv6 loopback across the `http.get`, `http.request`, and `http.batch` modules. | CVSS3: 7.7 | 0% Низкий | около 1 месяца назад | |
GHSA-35jm-qwg4-c8wj Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-35jj-wx47-4w8r WeasyPrint allows the attachment of arbitrary files and URLs to a PDF | CVSS3: 7.4 | 1% Низкий | больше 2 лет назад | |
GHSA-35jj-vqcf-f2jf Hidden fields can be leaked on readable collections in Payload | CVSS3: 7.4 | 1% Низкий | больше 3 лет назад | |
GHSA-35jj-h5xp-mhvc Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18. | CVSS3: 7.1 | 0% Низкий | почти 2 года назад | |
GHSA-35jj-9635-2vjm Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic. | 6% Низкий | больше 4 лет назад | ||
GHSA-35jj-42hp-8gmq n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket | 0% Низкий | 9 дней назад | ||
GHSA-35jh-r3h4-6jhm Command Injection in lodash | CVSS3: 7.2 | 21% Средний | больше 5 лет назад | |
GHSA-35jh-p5wf-6gg4 Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents. | 4% Низкий | больше 4 лет назад | ||
GHSA-35jh-g8qg-jgf5 Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite. | 8% Низкий | больше 4 лет назад | ||
GHSA-35jh-78c5-6rfj IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-35jh-65jp-wj73 Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote). | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-35jh-2r79-5r66 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767. | CVSS3: 7.5 | 87% Высокий | больше 4 лет назад | |
GHSA-35jg-8pwm-5q3v Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). | 0% Низкий | больше 4 лет назад | ||
GHSA-35jf-jfrv-9p25 The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-35jf-fw8j-m7v3 Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access. | 1% Низкий | больше 4 лет назад | ||
GHSA-35jc-cjp6-54c4 Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-35jc-5h4r-p9cg Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | CVSS3: 8.8 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу