Количество 325 632
Количество 325 632
GHSA-xq2q-96g9-r4pc
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.
GHSA-xq2q-8hxc-7jr2
XXE vulnerability in Jenkins Valgrind Plugin
GHSA-xq2p-cgwj-87m3
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.
GHSA-xq2p-83g5-rqxp
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.
GHSA-xq2m-jgm3-gpjw
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.
GHSA-xq2m-h4jc-ghmf
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
GHSA-xq2m-9f8c-rr6w
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.
GHSA-xq2j-fg32-wv9c
A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
GHSA-xq2j-2jwj-gfcq
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
GHSA-xq2h-vm9v-fgph
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.
GHSA-xq2h-p299-vjwv
Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade
GHSA-xq2h-7fp3-456v
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
GHSA-xq2h-74x7-89f4
Windows DNS Elevation of Privilege Vulnerability
GHSA-xq2g-qh2c-29p8
Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
GHSA-xq2g-73fq-x4mq
Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.
GHSA-xq2f-wc3r-4q96
Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.
GHSA-xq2f-h2vw-352p
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.
GHSA-xq2f-f4gq-58p8
The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
GHSA-xq2c-xc9f-44f4
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
GHSA-xq29-jcj7-xg86
Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xq2q-96g9-r4pc TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg. | CVSS3: 9.8 | 20% Средний | почти 4 года назад | |
GHSA-xq2q-8hxc-7jr2 XXE vulnerability in Jenkins Valgrind Plugin | CVSS3: 7.1 | 0% Низкий | почти 4 года назад | |
GHSA-xq2p-cgwj-87m3 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. | 10% Низкий | почти 4 года назад | ||
GHSA-xq2p-83g5-rqxp Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint. | CVSS3: 9.8 | 0% Низкий | 2 месяца назад | |
GHSA-xq2m-jgm3-gpjw Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file. | 54% Средний | почти 4 года назад | ||
GHSA-xq2m-h4jc-ghmf Tanium addressed an incorrect default permissions vulnerability in Partner Integration. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-xq2m-9f8c-rr6w LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files. | 0% Низкий | почти 4 года назад | ||
GHSA-xq2j-fg32-wv9c A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xq2j-2jwj-gfcq TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg. | CVSS3: 9.8 | 2% Низкий | около 1 года назад | |
GHSA-xq2h-vm9v-fgph Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields. | CVSS3: 4.7 | 0% Низкий | около 2 лет назад | |
GHSA-xq2h-p299-vjwv Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade | 0% Низкий | около 1 месяца назад | ||
GHSA-xq2h-7fp3-456v The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. | CVSS3: 6.8 | 0% Низкий | около 1 года назад | |
GHSA-xq2h-74x7-89f4 Windows DNS Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-xq2g-qh2c-29p8 Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CVSS3: 3.8 | 0% Низкий | 5 месяцев назад | |
GHSA-xq2g-73fq-x4mq Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6. | CVSS3: 7.1 | 0% Низкий | 7 месяцев назад | |
GHSA-xq2f-wc3r-4q96 Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document. | 1% Низкий | почти 4 года назад | ||
GHSA-xq2f-h2vw-352p Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-xq2f-f4gq-58p8 The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | CVSS3: 8.1 | 0% Низкий | 10 месяцев назад | |
GHSA-xq2c-xc9f-44f4 SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting. | 0% Низкий | почти 4 года назад | ||
GHSA-xq29-jcj7-xg86 Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу