Количество 357 271
Количество 357 271
GHSA-23p3-rx33-wm34
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
GHSA-23p3-9m3p-qpwp
Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
GHSA-23p2-2jrp-5wcp
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
GHSA-23mx-m43g-r4fh
The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
GHSA-23mx-4w8p-jgwp
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
GHSA-23mw-hwq9-w4q8
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
GHSA-23mr-m7vf-wgmp
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.
GHSA-23mr-c4wx-m5rr
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.
GHSA-23mm-fp65-w636
Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-23mm-62vv-wv83
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
GHSA-23mj-f5f2-4h46
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.
GHSA-23mh-p5gr-48gh
SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
GHSA-23mh-jxf4-vm3h
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
GHSA-23mg-qphc-9fg5
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
GHSA-23mg-57wx-h29h
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.
GHSA-23mf-2ffr-xmv9
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
GHSA-23mc-xgfq-qhjf
The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.
GHSA-23mc-xgfj-48f2
Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.
GHSA-23m9-rr4p-xpwh
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.
GHSA-23m7-v83h-jpr5
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-23p3-rx33-wm34 An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. | 1% Низкий | около 4 лет назад | ||
GHSA-23p3-9m3p-qpwp Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-23p2-2jrp-5wcp In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-23mx-m43g-r4fh The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | CVSS3: 4.7 | 0% Низкий | около 1 года назад | |
GHSA-23mx-4w8p-jgwp Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions. | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-23mw-hwq9-w4q8 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-23mr-m7vf-wgmp The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. | 3% Низкий | около 4 лет назад | ||
GHSA-23mr-c4wx-m5rr A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-23mm-fp65-w636 Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.3 | 0% Низкий | больше 3 лет назад | |
GHSA-23mm-62vv-wv83 SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | CVSS3: 7.2 | 68% Средний | почти 4 года назад | |
GHSA-23mj-f5f2-4h46 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input. | CVSS3: 8.8 | 3% Низкий | больше 1 года назад | |
GHSA-23mh-p5gr-48gh SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-23mh-jxf4-vm3h Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | 6% Низкий | около 4 лет назад | ||
GHSA-23mg-qphc-9fg5 Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences. | 3% Низкий | больше 4 лет назад | ||
GHSA-23mg-57wx-h29h interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image. | 3% Низкий | около 4 лет назад | ||
GHSA-23mf-2ffr-xmv9 Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | CVSS3: 9.8 | 17% Средний | больше 4 лет назад | |
GHSA-23mc-xgfq-qhjf The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog. | 1% Низкий | около 4 лет назад | ||
GHSA-23mc-xgfj-48f2 Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-23m9-rr4p-xpwh Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-23m7-v83h-jpr5 There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу