Количество 325 176
Количество 325 176
GHSA-xqgc-3m6w-h9jw
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.
GHSA-xqg9-jvvp-rh48
Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter.
GHSA-xqg9-hvp9-6pqp
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.
GHSA-xqg9-33x5-6qjg
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.
GHSA-xqg8-j998-6rqv
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
GHSA-xqg8-fm8q-c2p5
In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-xqg8-cv3h-xppv
SQL Injection in sequelize
GHSA-xqg8-9xv8-w5j8
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
GHSA-xqg7-w425-fm4c
Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.
GHSA-xqg7-m89g-c8qg
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.
GHSA-xqg6-prcj-86cv
NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.
GHSA-xqg6-p6hx-f752
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.
GHSA-xqg6-98cw-gxhq
Prototype Pollution via FormData Processing in Qwik City
GHSA-xqg5-vgfp-2g7g
Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
GHSA-xqg5-r78q-7wrx
Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration allows Cross Site Request Forgery. This issue affects TrustMate.io – WooCommerce integration: from n/a through 1.14.0.
GHSA-xqg5-5x64-93r9
A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xqg4-rm9f-hv4c
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-xqg4-63rp-xhx6
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
GHSA-xqg3-vx4p-jmwm
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
GHSA-xqg2-r5rv-62x6
Solaris ufsrestore buffer overflow.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xqgc-3m6w-h9jw XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165. | 0% Низкий | почти 4 года назад | ||
GHSA-xqg9-jvvp-rh48 Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-xqg9-hvp9-6pqp Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110. | 11% Средний | почти 4 года назад | ||
GHSA-xqg9-33x5-6qjg ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems. | 1% Низкий | почти 4 года назад | ||
GHSA-xqg8-j998-6rqv Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system. | 1% Низкий | почти 4 года назад | ||
GHSA-xqg8-fm8q-c2p5 In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
GHSA-xqg8-cv3h-xppv SQL Injection in sequelize | 0% Низкий | больше 8 лет назад | ||
GHSA-xqg8-9xv8-w5j8 Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename. | 1% Низкий | почти 4 года назад | ||
GHSA-xqg7-w425-fm4c Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-xqg7-m89g-c8qg PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php. | 1% Низкий | почти 4 года назад | ||
GHSA-xqg6-prcj-86cv NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xqg6-p6hx-f752 OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces. | CVSS3: 7.5 | 0% Низкий | 8 дней назад | |
GHSA-xqg6-98cw-gxhq Prototype Pollution via FormData Processing in Qwik City | CVSS3: 9.3 | 0% Низкий | 2 месяца назад | |
GHSA-xqg5-vgfp-2g7g Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-xqg5-r78q-7wrx Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration allows Cross Site Request Forgery. This issue affects TrustMate.io – WooCommerce integration: from n/a through 1.14.0. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
GHSA-xqg5-5x64-93r9 A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | около 1 месяца назад | |
GHSA-xqg4-rm9f-hv4c A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад | |
GHSA-xqg4-63rp-xhx6 Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. | CVSS3: 9.8 | 3% Низкий | почти 4 года назад | |
GHSA-xqg3-vx4p-jmwm A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | CVSS3: 6.6 | 33% Средний | больше 1 года назад | |
GHSA-xqg2-r5rv-62x6 Solaris ufsrestore buffer overflow. | CVSS3: 8.4 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу