Количество 357 271
Количество 357 271
GHSA-xp5q-77mh-6hm2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
GHSA-xp5q-5q7g-q26r
Ludwig framework is vulnerable to insecure deserialization in its model serving component
GHSA-xp5p-m9rq-h59j
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.
GHSA-xp5p-5cr9-v76h
Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session
GHSA-xp5m-682p-74cw
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
GHSA-xp5m-4c9f-498q
django-epiceditor vulnerable to XSS in form field
GHSA-xp5m-3m34-5m96
The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.
GHSA-xp5j-wj4h-2jq9
Injection and Improper Input Validation in Apache Unomi
GHSA-xp5j-hrqw-xvpc
In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.
GHSA-xp5j-75x6-qx28
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.
GHSA-xp5h-f8jf-rc8q
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
GHSA-xp5g-whvx-3f7g
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
GHSA-xp5g-v8fx-97mv
An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).
GHSA-xp5g-jhg3-3rg2
Double spend in snarkjs
GHSA-xp5g-gff9-qvvx
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
GHSA-xp5f-4q2v-q3xf
A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-xp5c-p5xg-fx95
Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.
GHSA-xp58-v8qq-x8jr
In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel
GHSA-xp58-h76m-67p4
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
GHSA-xp57-8544-jh3m
WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xp5q-77mh-6hm2 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
GHSA-xp5q-5q7g-q26r Ludwig framework is vulnerable to insecure deserialization in its model serving component | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-xp5p-m9rq-h59j Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xp5p-5cr9-v76h Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session | CVSS3: 6.1 | 0% Низкий | 7 месяцев назад | |
GHSA-xp5m-682p-74cw eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values. | 1% Низкий | больше 4 лет назад | ||
GHSA-xp5m-4c9f-498q django-epiceditor vulnerable to XSS in form field | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
GHSA-xp5m-3m34-5m96 The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xp5j-wj4h-2jq9 Injection and Improper Input Validation in Apache Unomi | CVSS3: 9.8 | 68% Средний | больше 4 лет назад | |
GHSA-xp5j-hrqw-xvpc In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-xp5j-75x6-qx28 awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname. | 3% Низкий | около 4 лет назад | ||
GHSA-xp5h-f8jf-rc8q rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements | CVSS3: 6.3 | 1% Низкий | около 3 лет назад | |
GHSA-xp5g-whvx-3f7g In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-xp5g-v8fx-97mv An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data). | CVSS3: 7.5 | 42% Средний | около 4 лет назад | |
GHSA-xp5g-jhg3-3rg2 Double spend in snarkjs | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-xp5g-gff9-qvvx There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-xp5f-4q2v-q3xf A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-xp5c-p5xg-fx95 Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request. | 3% Низкий | около 4 лет назад | ||
GHSA-xp58-v8qq-x8jr In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel | 0% Низкий | около 4 лет назад | ||
GHSA-xp58-h76m-67p4 Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking." | 6% Низкий | около 4 лет назад | ||
GHSA-xp57-8544-jh3m WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу