Количество 375 268
Количество 375 268
GHSA-258m-qv8h-28wx
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.
GHSA-258m-ggv2-xxv3
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.
GHSA-258j-hjx4-w4m2
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
GHSA-258j-9683-m467
STOMP codec content-length long-to-int truncation causes infinite decode loop DoS
GHSA-258j-7hr2-w66m
Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action.
GHSA-258h-f687-4226
PheonixAppAPI has visible Encoding Maps
GHSA-258g-4g7h-f495
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External E...
GHSA-258f-pc8p-3mqr
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
GHSA-258f-3vwc-4rjv
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-258c-h3vm-64r5
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
GHSA-258c-cqq8-pmrp
Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
GHSA-258c-965c-p3hc
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
GHSA-258c-748x-qf4g
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
GHSA-2589-w6xf-983r
Cross-site scripting in react-bootstrap-table
GHSA-2589-r26x-mh8p
ChakraCore RCE Vulnerability
GHSA-2589-88hx-72gf
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
GHSA-2589-6chq-5gj4
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.
GHSA-2588-cx6w-6vm6
Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials
GHSA-2587-w93g-63m2
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files
GHSA-2587-cwc2-rm4f
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-258m-qv8h-28wx IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986. | 1% Низкий | больше 4 лет назад | ||
GHSA-258m-ggv2-xxv3 When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-258j-hjx4-w4m2 Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-258j-9683-m467 STOMP codec content-length long-to-int truncation causes infinite decode loop DoS | CVSS3: 7.5 | 1 день назад | ||
GHSA-258j-7hr2-w66m Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action. | CVSS3: 9.8 | 1% Низкий | 8 месяцев назад | |
GHSA-258h-f687-4226 PheonixAppAPI has visible Encoding Maps | CVSS3: 4.4 | 0% Низкий | около 2 лет назад | |
GHSA-258g-4g7h-f495 Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External E... | 1% Низкий | больше 4 лет назад | ||
GHSA-258f-pc8p-3mqr Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N). | CVSS3: 4.8 | 0% Низкий | около 1 месяца назад | |
GHSA-258f-3vwc-4rjv The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 1% Низкий | почти 3 года назад | |
GHSA-258c-h3vm-64r5 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | около 1 года назад | |
GHSA-258c-cqq8-pmrp Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords. | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
GHSA-258c-965c-p3hc Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change | CVSS3: 6.5 | 5 месяцев назад | ||
GHSA-258c-748x-qf4g Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2. | CVSS3: 4.6 | 0% Низкий | больше 1 года назад | |
GHSA-2589-w6xf-983r Cross-site scripting in react-bootstrap-table | CVSS3: 6.1 | 1% Низкий | почти 5 лет назад | |
GHSA-2589-r26x-mh8p ChakraCore RCE Vulnerability | CVSS3: 7.5 | 14% Средний | больше 4 лет назад | |
GHSA-2589-88hx-72gf IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
GHSA-2589-6chq-5gj4 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit. | 1% Низкий | больше 4 лет назад | ||
GHSA-2588-cx6w-6vm6 Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-2587-w93g-63m2 Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-2587-cwc2-rm4f Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.4 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу