Количество 376 080
Количество 376 080
GHSA-xr4j-2qp3-r4xc
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
GHSA-xr4h-xg4j-4v8c
Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-xr4h-93hj-62q2
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
GHSA-xr4g-wmqx-7w9w
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
GHSA-xr4g-93qp-pf58
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
GHSA-xr4f-pqj2-jwc5
Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.
GHSA-xr4f-mjxj-w6w5
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
GHSA-xr4f-cr86-pfhv
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
GHSA-xr4f-2rrr-cm48
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
GHSA-xr4c-xrjh-v47v
Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
GHSA-xr4c-mmrv-3h6c
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-xr4c-88wp-frr7
Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."
GHSA-xr49-qh48-cff9
Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.
GHSA-xr49-pr22-vxc8
Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.
GHSA-xr49-f4rh-qcjf
AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
GHSA-xr49-8593-rwjh
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
GHSA-xr49-7fhc-h2jh
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.
GHSA-xr48-rvqv-pwjm
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
GHSA-xr47-pcmx-fq2m
Certain sequence of payloads may lead to remote code execution
GHSA-xr47-8jmm-28wq
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xr4j-2qp3-r4xc The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xr4h-xg4j-4v8c Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | больше 3 лет назад | |
GHSA-xr4h-93hj-62q2 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | около 2 лет назад | |
GHSA-xr4g-wmqx-7w9w The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-xr4g-93qp-pf58 Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory. | 0% Низкий | больше 4 лет назад | ||
GHSA-xr4f-pqj2-jwc5 Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11. | 0% Низкий | больше 4 лет назад | ||
GHSA-xr4f-mjxj-w6w5 OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes | CVSS3: 8.3 | 3 месяца назад | ||
GHSA-xr4f-cr86-pfhv Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools. | CVSS3: 4.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xr4f-2rrr-cm48 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2. | CVSS3: 8.8 | 1% Низкий | почти 3 года назад | |
GHSA-xr4c-xrjh-v47v Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 3.1 | 0% Низкий | 5 месяцев назад | |
GHSA-xr4c-mmrv-3h6c there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.4 | 0% Низкий | около 2 лет назад | |
GHSA-xr4c-88wp-frr7 Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier." | 6% Низкий | больше 4 лет назад | ||
GHSA-xr49-qh48-cff9 Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component. | CVSS3: 9.1 | 1% Низкий | больше 2 лет назад | |
GHSA-xr49-pr22-vxc8 Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code. | 1% Низкий | больше 4 лет назад | ||
GHSA-xr49-f4rh-qcjf AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization | 0% Низкий | 5 месяцев назад | ||
GHSA-xr49-8593-rwjh An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-xr49-7fhc-h2jh A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008. | CVSS3: 5.5 | 1% Низкий | почти 4 года назад | |
GHSA-xr48-rvqv-pwjm An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | CVSS3: 8.8 | 6% Низкий | больше 4 лет назад | |
GHSA-xr47-pcmx-fq2m Certain sequence of payloads may lead to remote code execution | CVSS3: 8.1 | 3% Низкий | больше 2 лет назад | |
GHSA-xr47-8jmm-28wq A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу