Количество 355 704
Количество 355 704
GHSA-xpx7-5x44-3fqq
IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
GHSA-xpx7-27p8-r55q
IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.
GHSA-xpx6-hwxg-rj79
The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-xpx5-8gpf-9924
Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.
GHSA-xpx4-57h5-9v98
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.
GHSA-xpx2-vc3f-pg29
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.
GHSA-xpww-g9jx-hp8r
Miscomputed sha2 results when using AVX2 backend
GHSA-xpww-f6pm-cfhq
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
GHSA-xpwv-rp39-7pr7
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.
GHSA-xpwv-gcc7-5gwp
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
GHSA-xpwv-75x9-38q4
Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.
GHSA-xpwr-42qv-5j22
Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.
GHSA-xpwq-w665-cf7c
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
GHSA-xpwq-r3f8-686w
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
GHSA-xpwq-h27p-5wg9
FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.
GHSA-xpwq-6mfc-rr7g
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
GHSA-xpwp-rq3x-x6v7
Critical severity vulnerability that affects recurly-api-client
GHSA-xpwp-hgm6-qgh5
Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.
GHSA-xpwm-vrv5-5mgm
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
GHSA-xpwm-m5cr-whm7
A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xpx7-5x44-3fqq IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
GHSA-xpx7-27p8-r55q IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly. | 1% Низкий | больше 4 лет назад | ||
GHSA-xpx6-hwxg-rj79 The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | около 4 лет назад | ||
GHSA-xpx5-8gpf-9924 Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17. | CVSS3: 8.8 | 0% Низкий | 9 месяцев назад | |
GHSA-xpx4-57h5-9v98 A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization. | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
GHSA-xpx2-vc3f-pg29 SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action. | 1% Низкий | около 4 лет назад | ||
GHSA-xpww-g9jx-hp8r Miscomputed sha2 results when using AVX2 backend | около 4 лет назад | |||
GHSA-xpww-f6pm-cfhq dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
GHSA-xpwv-rp39-7pr7 Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-xpwv-gcc7-5gwp In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xpwv-75x9-38q4 Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xpwr-42qv-5j22 Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19. | 3% Низкий | больше 4 лет назад | ||
GHSA-xpwq-w665-cf7c Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability." | 21% Средний | больше 4 лет назад | ||
GHSA-xpwq-r3f8-686w Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-xpwq-h27p-5wg9 FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function. | CVSS3: 8.8 | 2% Низкий | почти 4 года назад | |
GHSA-xpwq-6mfc-rr7g Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-xpwp-rq3x-x6v7 Critical severity vulnerability that affects recurly-api-client | 3% Низкий | почти 8 лет назад | ||
GHSA-xpwp-hgm6-qgh5 Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html. | 1% Низкий | больше 4 лет назад | ||
GHSA-xpwm-vrv5-5mgm A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password. | CVSS3: 8.6 | 1% Низкий | почти 2 года назад | |
GHSA-xpwm-m5cr-whm7 A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394. | CVSS3: 7.5 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу