Количество 326 185
Количество 326 185
GHSA-xmqf-c7cr-275p
Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502.
GHSA-xmqf-6397-gmvx
Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.
GHSA-xmqc-9cfr-hg4r
A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xmq9-qw99-3695
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
GHSA-xmq8-c3h6-wf48
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.
GHSA-xmq7-vcg4-jfj9
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
GHSA-xmq7-7fxm-rr79
Denial of Service in Tensorflow
GHSA-xmq6-3r6w-66pw
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.
GHSA-xmq4-6j6c-v6v5
article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.
GHSA-xmq3-w762-fqmr
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
GHSA-xmq3-q5pm-rp26
Nuxt DevTools vulnerable to cross-site scripting (XSS)
GHSA-xmq3-hgjx-6997
Cross-site Scripting in Pimcore
GHSA-xmq3-c6r3-6cm9
A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name.
GHSA-xmq2-m5xv-mwcj
u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55
GHSA-xmq2-8hhc-7629
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-xmq2-3xpw-g24h
IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.
GHSA-xmpx-2mhf-xq2j
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.
GHSA-xmpw-v77r-v8qg
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.
GHSA-xmpv-p68m-37pg
There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
GHSA-xmpv-j7p2-j873
Nautobot: Management of users via REST API does not apply configured password validators
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xmqf-c7cr-275p Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote attackers to execute arbitrary code via the downloadFileDirectory property, a different vulnerability than CVE-2006-5502. | 5% Низкий | почти 4 года назад | ||
GHSA-xmqf-6397-gmvx Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-xmqc-9cfr-hg4r A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-xmq9-qw99-3695 RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-xmq8-c3h6-wf48 This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xmq7-vcg4-jfj9 Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name. | CVSS3: 6.1 | 3% Низкий | почти 4 года назад | |
GHSA-xmq7-7fxm-rr79 Denial of Service in Tensorflow | CVSS3: 7.5 | 0% Низкий | больше 5 лет назад | |
GHSA-xmq6-3r6w-66pw The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xmq4-6j6c-v6v5 article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action. | 0% Низкий | почти 4 года назад | ||
GHSA-xmq3-w762-fqmr The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field. | 1% Низкий | почти 4 года назад | ||
GHSA-xmq3-q5pm-rp26 Nuxt DevTools vulnerable to cross-site scripting (XSS) | CVSS3: 6.9 | 0% Низкий | 5 месяцев назад | |
GHSA-xmq3-hgjx-6997 Cross-site Scripting in Pimcore | CVSS3: 5.4 | 0% Низкий | около 4 лет назад | |
GHSA-xmq3-c6r3-6cm9 A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with an XSS payload as the document name. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-xmq2-m5xv-mwcj u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55 | 0% Низкий | почти 4 года назад | ||
GHSA-xmq2-8hhc-7629 A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-xmq2-3xpw-g24h IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914. | CVSS3: 7.2 | 0% Низкий | почти 4 года назад | |
GHSA-xmpx-2mhf-xq2j An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked. | CVSS3: 3.3 | 0% Низкий | около 1 года назад | |
GHSA-xmpw-v77r-v8qg CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-xmpv-p68m-37pg There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0. | 0% Низкий | около 4 лет назад | ||
GHSA-xmpv-j7p2-j873 Nautobot: Management of users via REST API does not apply configured password validators | CVSS3: 2.7 | 0% Низкий | 13 дней назад |
Уязвимостей на страницу