Количество 376 080
Количество 376 080
GHSA-xr2h-wg3w-vrcr
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-xr2h-v539-xc2h
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xr2g-wg2c-hrx6
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
GHSA-xr2g-57fm-4f25
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-xr2f-69jg-7g6f
Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.
GHSA-xr2c-mwcx-4xmj
Buffer overflow in NIS+, in Sun's rpc.nisd program.
GHSA-xr2c-mghr-gmr2
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
GHSA-xr2c-6hv6-xcw7
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
GHSA-xr2c-5w89-63pv
Poetry before v1.1.9 contains Untrusted Search Path
GHSA-xr2c-56qc-4ffh
A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)
GHSA-xr2c-4prw-6479
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
GHSA-xr29-6gg3-jq8m
SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.
GHSA-xr29-4f97-vhvq
A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
GHSA-xr28-hrcf-5jw6
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.
GHSA-xr28-f4wv-gfp3
An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.
GHSA-xr27-wwfr-j97v
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
GHSA-xr27-v8wc-87cr
An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.
GHSA-xr26-qphw-jcg8
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
GHSA-xr25-qx3m-g53h
vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.
GHSA-xr25-hvc7-fcxm
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xr2h-wg3w-vrcr Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-xr2h-v539-xc2h A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.5 | 0% Низкий | 3 дня назад | |
GHSA-xr2g-wg2c-hrx6 Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xr2g-57fm-4f25 In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-xr2f-69jg-7g6f Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 4.4 | 0% Низкий | почти 2 года назад | |
GHSA-xr2c-mwcx-4xmj Buffer overflow in NIS+, in Sun's rpc.nisd program. | 4% Низкий | больше 4 лет назад | ||
GHSA-xr2c-mghr-gmr2 Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection | CVSS3: 6.8 | 0% Низкий | около 4 лет назад | |
GHSA-xr2c-6hv6-xcw7 Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. | около 2 месяцев назад | |||
GHSA-xr2c-5w89-63pv Poetry before v1.1.9 contains Untrusted Search Path | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xr2c-56qc-4ffh A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions) | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад | |
GHSA-xr2c-4prw-6479 PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. | CVSS3: 8 | 0% Низкий | больше 4 лет назад | |
GHSA-xr29-6gg3-jq8m SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xr29-4f97-vhvq A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | CVSS3: 6.3 | 0% Низкий | 7 месяцев назад | |
GHSA-xr28-hrcf-5jw6 Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565. | CVSS3: 4.7 | 0% Низкий | около 2 лет назад | |
GHSA-xr28-f4wv-gfp3 An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-xr27-wwfr-j97v CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xr27-v8wc-87cr An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-xr26-qphw-jcg8 Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xr25-qx3m-g53h vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals. | CVSS3: 5.3 | 0% Низкий | 6 дней назад | |
GHSA-xr25-hvc7-fcxm HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу