Количество 353 714
Количество 353 714
GHSA-224p-vx89-7gp5
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context.
GHSA-224p-v68g-5g8f
GraphQL Armor Max-Depth Plugin Bypass via fragment caching
GHSA-224p-qx2h-m4rg
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
GHSA-224p-qr6q-c376
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
GHSA-224p-h66f-prf2
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
GHSA-224p-6f6c-j2f6
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
GHSA-224m-8wrv-4v8r
Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.
GHSA-224m-5fj7-xcf7
Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
GHSA-224j-3632-5gqr
The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given attachment. This action is accessible for user accounts with the ‘manage_options’ privilege (i.e.., only administrators). Unfortunately, one of the parameters used in this AJAX endpoint is not sanitized before being printed back to the user, so the risk it represents is the same as the previous XSS vulnerability.
GHSA-224h-vf26-wvfw
The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.
GHSA-224h-p7p5-rh85
Directory Traversal in wenluhong1
GHSA-224h-mqw6-642p
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
GHSA-224h-m2mg-r929
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
GHSA-224g-q27w-pv8f
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
GHSA-224g-5gvw-3m56
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt to launch a grid without previously providing a Compute Shader (CS).
GHSA-224f-wm46-5p4r
An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
GHSA-224f-2jgg-f9vc
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.
GHSA-224c-qxxc-fqx7
login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.
GHSA-224c-7qmf-qhq6
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Retention and Spam Policies page.
GHSA-224c-5v2c-j3fr
Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction allows Cross Site Request Forgery. This issue affects Simple Page Access Restriction: from n/a through 1.0.32.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-224p-vx89-7gp5 Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-224p-v68g-5g8f GraphQL Armor Max-Depth Plugin Bypass via fragment caching | CVSS3: 5.3 | 11 месяцев назад | ||
GHSA-224p-qx2h-m4rg A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request. | 1% Низкий | около 4 лет назад | ||
GHSA-224p-qr6q-c376 Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass." | 31% Средний | около 4 лет назад | ||
GHSA-224p-h66f-prf2 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | CVSS3: 5.9 | 2% Низкий | около 3 лет назад | |
GHSA-224p-6f6c-j2f6 Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link. | CVSS3: 3.1 | 0% Низкий | 10 месяцев назад | |
GHSA-224m-8wrv-4v8r Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs. | 2% Низкий | около 4 лет назад | ||
GHSA-224m-5fj7-xcf7 Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-224j-3632-5gqr The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given attachment. This action is accessible for user accounts with the ‘manage_options’ privilege (i.e.., only administrators). Unfortunately, one of the parameters used in this AJAX endpoint is not sanitized before being printed back to the user, so the risk it represents is the same as the previous XSS vulnerability. | 2% Низкий | около 4 лет назад | ||
GHSA-224h-vf26-wvfw The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
GHSA-224h-p7p5-rh85 Directory Traversal in wenluhong1 | CVSS3: 7.5 | почти 6 лет назад | ||
GHSA-224h-mqw6-642p The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5. | 1% Низкий | больше 4 лет назад | ||
GHSA-224h-m2mg-r929 DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-224g-q27w-pv8f Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL. | CVSS3: 6.1 | 5% Низкий | около 4 лет назад | |
GHSA-224g-5gvw-3m56 A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt to launch a grid without previously providing a Compute Shader (CS). | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-224f-wm46-5p4r An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request. | CVSS3: 6.2 | 0% Низкий | 6 месяцев назад | |
GHSA-224f-2jgg-f9vc Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461. | 60% Средний | около 4 лет назад | ||
GHSA-224c-qxxc-fqx7 login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok. | 0% Низкий | больше 4 лет назад | ||
GHSA-224c-7qmf-qhq6 GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Retention and Spam Policies page. | CVSS3: 5.4 | 0% Низкий | 9 дней назад | |
GHSA-224c-5v2c-j3fr Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction allows Cross Site Request Forgery. This issue affects Simple Page Access Restriction: from n/a through 1.0.32. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу