Количество 360 872
Количество 360 872
GHSA-23p4-qm9x-842q
Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.
GHSA-23p4-5ppc-536p
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.
GHSA-23p3-vg9x-qw6p
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
GHSA-23p3-vcf6-94xq
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
GHSA-23p3-rx33-wm34
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
GHSA-23p3-9m3p-qpwp
Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
GHSA-23p2-2jrp-5wcp
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
GHSA-23mx-m43g-r4fh
The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
GHSA-23mx-4w8p-jgwp
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
GHSA-23mw-hwq9-w4q8
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
GHSA-23mr-m7vf-wgmp
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.
GHSA-23mr-c4wx-m5rr
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.
GHSA-23mm-fp65-w636
Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-23mm-62vv-wv83
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
GHSA-23mj-f5f2-4h46
An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.
GHSA-23mh-p5gr-48gh
SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
GHSA-23mh-jxf4-vm3h
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
GHSA-23mg-qphc-9fg5
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
GHSA-23mg-c4fv-vfxj
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
GHSA-23mg-57wx-h29h
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-23p4-qm9x-842q Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-23p4-5ppc-536p Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form. | 3% Низкий | больше 4 лет назад | ||
GHSA-23p3-vg9x-qw6p Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | 2% Низкий | больше 4 лет назад | ||
GHSA-23p3-vcf6-94xq An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-23p3-rx33-wm34 An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. | 1% Низкий | около 4 лет назад | ||
GHSA-23p3-9m3p-qpwp Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-23p2-2jrp-5wcp In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-23mx-m43g-r4fh The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | CVSS3: 4.7 | 0% Низкий | около 1 года назад | |
GHSA-23mx-4w8p-jgwp Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions. | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
GHSA-23mw-hwq9-w4q8 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-23mr-m7vf-wgmp The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. | 3% Низкий | больше 4 лет назад | ||
GHSA-23mr-c4wx-m5rr A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-23mm-fp65-w636 Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.3 | 0% Низкий | больше 3 лет назад | |
GHSA-23mm-62vv-wv83 SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | CVSS3: 7.2 | 68% Средний | почти 4 года назад | |
GHSA-23mj-f5f2-4h46 An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input. | CVSS3: 8.8 | 3% Низкий | больше 1 года назад | |
GHSA-23mh-p5gr-48gh SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-23mh-jxf4-vm3h Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | 6% Низкий | больше 4 лет назад | ||
GHSA-23mg-qphc-9fg5 Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences. | 3% Низкий | больше 4 лет назад | ||
GHSA-23mg-c4fv-vfxj The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption. | CVSS3: 5.4 | 0% Низкий | 1 день назад | |
GHSA-23mg-57wx-h29h interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image. | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу