Количество 325 176
Количество 325 176
GHSA-xqfj-35wv-m3cr
Null pointer dereference in `StringNGrams`
GHSA-xqfh-gx6q-m574
Rejected reason: Not used
GHSA-xqfg-p7f2-6w5f
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
GHSA-xqff-x4hf-x674
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.
GHSA-xqff-gxc3-2x4v
The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
GHSA-xqfc-fqm7-gx4x
A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.
GHSA-xqfc-cx8v-9v3h
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.
GHSA-xqfc-ch67-qwvg
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
GHSA-xqf9-v7ff-rf4x
Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.
GHSA-xqf9-qrgq-fxfv
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.
GHSA-xqf9-q644-qr8q
HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.
GHSA-xqf7-wh6f-f6jh
The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xqf7-frvw-5523
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
GHSA-xqf6-p37p-9cxg
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.
GHSA-xqf6-m6vx-v7jx
Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.
GHSA-xqf6-9hf7-323f
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.
GHSA-xqf6-5grh-6223
Passwords transmitted in plain text by Jenkins Artifactory Plugin
GHSA-xqf5-6fm4-qwhv
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.
GHSA-xqf3-q69c-jc7c
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
GHSA-xqf3-q2jh-qp3h
Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xqfj-35wv-m3cr Null pointer dereference in `StringNGrams` | CVSS3: 2.5 | 0% Низкий | почти 5 лет назад | |
GHSA-xqfh-gx6q-m574 Rejected reason: Not used | около 2 месяцев назад | |||
GHSA-xqfg-p7f2-6w5f An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xqff-x4hf-x674 Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used. | 0% Низкий | почти 4 года назад | ||
GHSA-xqff-gxc3-2x4v The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-xqfc-fqm7-gx4x A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xqfc-cx8v-9v3h A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675. | CVSS3: 7.8 | 30% Средний | почти 4 года назад | |
GHSA-xqfc-ch67-qwvg In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xqf9-v7ff-rf4x Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-xqf9-qrgq-fxfv In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-xqf9-q644-qr8q HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb. | 1% Низкий | почти 4 года назад | ||
GHSA-xqf7-wh6f-f6jh The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
GHSA-xqf7-frvw-5523 In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xqf6-p37p-9cxg A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-xqf6-m6vx-v7jx Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xqf6-9hf7-323f An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-xqf6-5grh-6223 Passwords transmitted in plain text by Jenkins Artifactory Plugin | CVSS3: 3.1 | 0% Низкий | почти 4 года назад | |
GHSA-xqf5-6fm4-qwhv Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server. | 0% Низкий | почти 4 года назад | ||
GHSA-xqf3-q69c-jc7c Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions. | CVSS3: 4.6 | 0% Низкий | больше 1 года назад | |
GHSA-xqf3-q2jh-qp3h Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.3 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу