Количество 326 121
Количество 326 121
GHSA-xmw9-6v8p-w6jg
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
GHSA-xmw9-6r43-x9ww
SiYuan has directory traversal within its publishing service
GHSA-xmw7-wmp8-hj98
Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.
GHSA-xmw7-pfh7-ccxp
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
GHSA-xmw7-848p-p95w
Airbnb Knowledge Repo XSS In Comments
GHSA-xmw5-45v9-pxqx
XSS vulnerability in Jenkins TICS Plugin
GHSA-xmw4-wxv9-hm5g
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
GHSA-xmw3-64p4-g77h
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.
GHSA-xmw2-mw3c-793w
Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.
GHSA-xmw2-h4mh-h75v
Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
GHSA-xmw2-9pgq-w58j
The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.
GHSA-xmw2-9fv2-vx29
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.
GHSA-xmw2-8pp9-3q4c
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-xmw2-2pgj-jq4h
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
GHSA-xmvx-xxj4-g48f
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.
GHSA-xmvx-vh6j-5wm2
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
GHSA-xmvw-m3jj-qhfh
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.
GHSA-xmvv-w44w-j8wx
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
GHSA-xmvv-4vx6-5fqj
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
GHSA-xmvq-j2gc-q94f
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xmw9-6v8p-w6jg Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." | 0% Низкий | почти 4 года назад | ||
GHSA-xmw9-6r43-x9ww SiYuan has directory traversal within its publishing service | CVSS3: 9.8 | 0% Низкий | 18 дней назад | |
GHSA-xmw7-wmp8-hj98 Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. | 0% Низкий | почти 4 года назад | ||
GHSA-xmw7-pfh7-ccxp The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xmw7-848p-p95w Airbnb Knowledge Repo XSS In Comments | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xmw5-45v9-pxqx XSS vulnerability in Jenkins TICS Plugin | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xmw4-wxv9-hm5g Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). | CVSS3: 3.5 | 0% Низкий | больше 1 года назад | |
GHSA-xmw3-64p4-g77h Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
GHSA-xmw2-mw3c-793w Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination. | 0% Низкий | почти 4 года назад | ||
GHSA-xmw2-h4mh-h75v Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-xmw2-9pgq-w58j The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet. | 0% Низкий | почти 4 года назад | ||
GHSA-xmw2-9fv2-vx29 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xmw2-8pp9-3q4c SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-xmw2-2pgj-jq4h Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | 0% Низкий | почти 4 года назад | ||
GHSA-xmvx-xxj4-g48f A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-xmvx-vh6j-5wm2 A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. | CVSS3: 9.8 | 3% Низкий | почти 4 года назад | |
GHSA-xmvw-m3jj-qhfh The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-xmvv-w44w-j8wx Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection | CVSS3: 3.3 | 0% Низкий | около 1 года назад | |
GHSA-xmvv-4vx6-5fqj The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account. | 4% Низкий | почти 4 года назад | ||
GHSA-xmvq-j2gc-q94f Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 6% Низкий | почти 4 года назад |
Уязвимостей на страницу