Количество 370 841
Количество 370 841
GHSA-24q3-549v-f57v
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
GHSA-24q3-2w85-x8p7
Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.
GHSA-24q2-qw2x-xxpj
The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.
GHSA-24q2-h758-fvwc
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
GHSA-24q2-f22j-vg5m
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.
GHSA-24q2-6x37-cgcx
Dolibarr SQL injection vulnerability in product/card.php
GHSA-24q2-59hm-rh9r
Strapi Improper Rate Limiting vulnerability
GHSA-24q2-4vqq-qcx6
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
GHSA-24px-m2q8-87hf
Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.
GHSA-24px-fh32-jvj7
Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-24pw-pfmp-w2w4
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https...
GHSA-24pw-p8jc-r7j5
SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.
GHSA-24pw-h6w3-6pgm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rewish WP Emmet allows Stored XSS. This issue affects WP Emmet: from n/a through 0.3.4.
GHSA-24pw-8cqg-3ppr
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access.
GHSA-24pv-x5f7-pv4r
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
GHSA-24pv-cxm8-65fp
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6.
GHSA-24pv-3jc8-2432
Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.
GHSA-24pr-9rc2-6xv5
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
GHSA-24pr-8ggp-h88c
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
GHSA-24pq-phfq-785f
Linear eMerge E3-Series devices allow Command Injections.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-24q3-549v-f57v SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. | 3% Низкий | больше 4 лет назад | ||
GHSA-24q3-2w85-x8p7 Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-24q2-qw2x-xxpj The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface. | 4% Низкий | больше 4 лет назад | ||
GHSA-24q2-h758-fvwc Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-24q2-f22j-vg5m Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass. | 1% Низкий | больше 4 лет назад | ||
GHSA-24q2-6x37-cgcx Dolibarr SQL injection vulnerability in product/card.php | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-24q2-59hm-rh9r Strapi Improper Rate Limiting vulnerability | CVSS3: 7.3 | 1% Низкий | почти 3 года назад | |
GHSA-24q2-4vqq-qcx6 User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-24px-m2q8-87hf Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7. | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
GHSA-24px-fh32-jvj7 Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-24pw-pfmp-w2w4 In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https... | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-24pw-p8jc-r7j5 SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-24pw-h6w3-6pgm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rewish WP Emmet allows Stored XSS. This issue affects WP Emmet: from n/a through 0.3.4. | CVSS3: 5.9 | 1% Низкий | около 1 года назад | |
GHSA-24pw-8cqg-3ppr An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
GHSA-24pv-x5f7-pv4r WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote ("). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-24pv-cxm8-65fp Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-24pv-3jc8-2432 Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-24pr-9rc2-6xv5 The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges. | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
GHSA-24pr-8ggp-h88c Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations. | CVSS3: 9.8 | 4% Низкий | 3 месяца назад | |
GHSA-24pq-phfq-785f Linear eMerge E3-Series devices allow Command Injections. | CVSS3: 10 | 97% Критический | больше 4 лет назад |
Уязвимостей на страницу