Количество 354 924
Количество 354 924
GHSA-227x-w5qv-2294
admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.
GHSA-227x-7mh8-3cf6
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
GHSA-227x-6m74-5g32
Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.
GHSA-227x-48c5-2jpf
HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.
GHSA-227w-xh58-rx2j
Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.
GHSA-227w-wv4j-67h4
Class Loading Vulnerability in Artemis
GHSA-227w-82c7-87qx
The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
GHSA-227v-w3r6-6vc4
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
GHSA-227v-m6p6-j6gx
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later
GHSA-227r-w5j2-6243
InvokeAI Arbitrary File Deletion vulnerability
GHSA-227r-vmhh-jq3x
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.
GHSA-227r-jm2g-7cp4
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
GHSA-227r-cc3q-mh85
Windows GDI+ Information Disclosure Vulnerability
GHSA-227p-wwrh-m869
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
GHSA-227p-7qgj-96v9
Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.
GHSA-227m-878m-h3qm
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.
GHSA-227j-xj2v-7f5v
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
GHSA-227h-wvc4-w9jx
In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.
GHSA-227h-6jwp-327q
A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-227g-p58c-6fwx
Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-227x-w5qv-2294 admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request. | 2% Низкий | больше 4 лет назад | ||
GHSA-227x-7mh8-3cf6 Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning | CVSS3: 9.9 | 0% Низкий | 11 месяцев назад | |
GHSA-227x-6m74-5g32 Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-227x-48c5-2jpf HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service. | 0% Низкий | около 4 лет назад | ||
GHSA-227w-xh58-rx2j Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages. | 1% Низкий | около 4 лет назад | ||
GHSA-227w-wv4j-67h4 Class Loading Vulnerability in Artemis | CVSS3: 8.2 | 0% Низкий | больше 4 лет назад | |
GHSA-227w-82c7-87qx The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | 2% Низкий | около 4 лет назад | ||
GHSA-227v-w3r6-6vc4 A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-227v-m6p6-j6gx A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-227r-w5j2-6243 InvokeAI Arbitrary File Deletion vulnerability | CVSS3: 9.1 | 1% Низкий | больше 1 года назад | |
GHSA-227r-vmhh-jq3x The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack. | 0% Низкий | 8 месяцев назад | ||
GHSA-227r-jm2g-7cp4 Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-227r-cc3q-mh85 Windows GDI+ Information Disclosure Vulnerability | CVSS3: 5.7 | 3% Низкий | около 4 лет назад | |
GHSA-227p-wwrh-m869 An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
GHSA-227p-7qgj-96v9 Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-227m-878m-h3qm A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-227j-xj2v-7f5v The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-227h-wvc4-w9jx In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-227h-6jwp-327q A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 7.3 | 1% Низкий | больше 2 лет назад | |
GHSA-227g-p58c-6fwx Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу