Количество 354 500
Количество 354 500
GHSA-223w-3rxg-p29x
Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions.
GHSA-223v-q737-hj53
Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.
GHSA-223r-m7gh-jxww
Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
GHSA-223r-j88r-q3hw
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name.
GHSA-223r-2r23-qr43
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
GHSA-223q-gr4m-8xc3
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
GHSA-223p-pjp4-9vv5
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.
GHSA-223p-m2w6-92v2
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
GHSA-223p-3v7f-rwxh
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to access sensitive user data.
GHSA-223m-pgcq-f3xg
Jenkins Fortify Plugin HTML injection vulnerability
GHSA-223m-mhgp-x54c
Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe payloads in the text parameter to store malicious content that executes in the browsers of users viewing the affected pages.
GHSA-223m-fhfm-47hr
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.
GHSA-223m-4rfp-646h
Jenkins is missing a permission check in the authenticated users' profile menu
GHSA-223j-w649-gh98
Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2.
GHSA-223j-8f9f-qhc5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.
GHSA-223j-7cj4-4cw7
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
GHSA-223j-4rm8-mrmf
Next.js may leak x-middleware-subrequest-id to external hosts
GHSA-223h-r336-f673
Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system.
GHSA-223h-642r-2f6v
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
GHSA-223g-f5mq-gw33
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-223w-3rxg-p29x Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-223v-q737-hj53 Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL. | 2% Низкий | больше 4 лет назад | ||
GHSA-223r-m7gh-jxww Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
GHSA-223r-j88r-q3hw Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name. | 2% Низкий | больше 4 лет назад | ||
GHSA-223r-2r23-qr43 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294. | 3% Низкий | около 4 лет назад | ||
GHSA-223q-gr4m-8xc3 In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-223p-pjp4-9vv5 An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-223p-m2w6-92v2 IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment. | CVSS3: 4.9 | 0% Низкий | больше 1 года назад | |
GHSA-223p-3v7f-rwxh This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to access sensitive user data. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-223m-pgcq-f3xg Jenkins Fortify Plugin HTML injection vulnerability | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-223m-mhgp-x54c Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe payloads in the text parameter to store malicious content that executes in the browsers of users viewing the affected pages. | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
GHSA-223m-fhfm-47hr PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php. | 6% Низкий | больше 4 лет назад | ||
GHSA-223m-4rfp-646h Jenkins is missing a permission check in the authenticated users' profile menu | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
GHSA-223j-w649-gh98 Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2. | CVSS3: 6.4 | 0% Низкий | 11 месяцев назад | |
GHSA-223j-8f9f-qhc5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-223j-7cj4-4cw7 Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0. | CVSS3: 9.1 | 0% Низкий | больше 1 года назад | |
GHSA-223j-4rm8-mrmf Next.js may leak x-middleware-subrequest-id to external hosts | 0% Низкий | больше 1 года назад | ||
GHSA-223h-r336-f673 Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system. | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
GHSA-223h-642r-2f6v A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow. | CVSS3: 6.8 | 0% Низкий | 14 дней назад | |
GHSA-223g-f5mq-gw33 OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу