Количество 326 121
Количество 326 121
GHSA-xp5q-j3fq-3qw3
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.
GHSA-xp5q-f74v-x8r5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.
GHSA-xp5q-c655-9565
The function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
GHSA-xp5q-77mh-6hm2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
GHSA-xp5p-m9rq-h59j
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.
GHSA-xp5p-5cr9-v76h
Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session
GHSA-xp5m-682p-74cw
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
GHSA-xp5m-4c9f-498q
django-epiceditor vulnerable to XSS in form field
GHSA-xp5m-3m34-5m96
The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.
GHSA-xp5j-wj4h-2jq9
Injection and Improper Input Validation in Apache Unomi
GHSA-xp5j-hrqw-xvpc
In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.
GHSA-xp5j-75x6-qx28
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
GHSA-xp5h-f8jf-rc8q
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
GHSA-xp5g-whvx-3f7g
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
GHSA-xp5g-v8fx-97mv
An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).
GHSA-xp5g-jhg3-3rg2
Double spend in snarkjs
GHSA-xp5g-gff9-qvvx
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
GHSA-xp5f-4q2v-q3xf
A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-xp5c-p5xg-fx95
Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.
GHSA-xp58-v8qq-x8jr
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xp5q-j3fq-3qw3 Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action. | 11% Средний | почти 4 года назад | ||
GHSA-xp5q-f74v-x8r5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a. | CVSS3: 7.1 | 0% Низкий | 8 месяцев назад | |
GHSA-xp5q-c655-9565 The function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-xp5q-77mh-6hm2 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xp5p-m9rq-h59j Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-xp5p-5cr9-v76h Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-xp5m-682p-74cw eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values. | 0% Низкий | почти 4 года назад | ||
GHSA-xp5m-4c9f-498q django-epiceditor vulnerable to XSS in form field | CVSS3: 6.1 | 0% Низкий | больше 7 лет назад | |
GHSA-xp5m-3m34-5m96 The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-xp5j-wj4h-2jq9 Injection and Improper Input Validation in Apache Unomi | CVSS3: 9.8 | 94% Критический | около 4 лет назад | |
GHSA-xp5j-hrqw-xvpc In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xp5j-75x6-qx28 awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname. | 1% Низкий | почти 4 года назад | ||
GHSA-xp5h-f8jf-rc8q rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements | CVSS3: 6.3 | 0% Низкий | почти 3 года назад | |
GHSA-xp5g-whvx-3f7g In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-xp5g-v8fx-97mv An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data). | CVSS3: 7.5 | 25% Средний | почти 4 года назад | |
GHSA-xp5g-jhg3-3rg2 Double spend in snarkjs | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-xp5g-gff9-qvvx There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-xp5f-4q2v-q3xf A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-xp5c-p5xg-fx95 Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request. | 0% Низкий | почти 4 года назад | ||
GHSA-xp58-v8qq-x8jr In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу