Количество 357 271
Количество 357 271
GHSA-xmxw-j4c5-629g
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions.
GHSA-xmxv-mcf7-rf26
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field.
GHSA-xmxr-5hxx-256r
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection. While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
GHSA-xmxp-x783-v5rx
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
GHSA-xmxp-gx58-3r75
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0536, CVE-2019-0549, CVE-2019-0554.
GHSA-xmxj-v2q8-8qx6
Concrete CMS Stored XSS in the "Next&Previous Nav" block
GHSA-xmxj-pp68-34rr
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xmxj-3326-2879
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.
GHSA-xmxh-qgmj-jcc4
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
GHSA-xmxh-pm35-h64j
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
GHSA-xmxh-g7wj-8m4m
OS Command Injection in curling
GHSA-xmxg-28xr-rp8x
drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor.
GHSA-xmxf-wjr9-rpwr
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
GHSA-xmxf-f859-45ch
Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.
GHSA-xmxf-9v5q-5mfw
A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
GHSA-xmxc-mvx2-q963
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.
GHSA-xmxc-8qjw-52gx
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.
GHSA-xmxc-2jc7-w66m
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
GHSA-xmx9-rjwq-m2x6
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
GHSA-xmx9-mmqw-jcw6
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xmxw-j4c5-629g Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-xmxv-mcf7-rf26 The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-xmxr-5hxx-256r Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Price Protection executes to compromise Oracle Price Protection. While the vulnerability is in Oracle Price Protection, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). | CVSS3: 8.4 | 0% Низкий | 22 дня назад | |
GHSA-xmxp-x783-v5rx Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-xmxp-gx58-3r75 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0536, CVE-2019-0549, CVE-2019-0554. | CVSS3: 5.5 | 2% Низкий | около 4 лет назад | |
GHSA-xmxj-v2q8-8qx6 Concrete CMS Stored XSS in the "Next&Previous Nav" block | CVSS3: 2.4 | 0% Низкий | почти 2 года назад | |
GHSA-xmxj-pp68-34rr Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 7 месяцев назад | |||
GHSA-xmxj-3326-2879 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2. | CVSS3: 8 | 0% Низкий | 10 месяцев назад | |
GHSA-xmxh-qgmj-jcc4 Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599. | CVSS3: 5.9 | 5% Низкий | около 4 лет назад | |
GHSA-xmxh-pm35-h64j A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform. | CVSS3: 6.8 | 1% Низкий | 8 месяцев назад | |
GHSA-xmxh-g7wj-8m4m OS Command Injection in curling | CVSS3: 9.8 | 5% Низкий | больше 5 лет назад | |
GHSA-xmxg-28xr-rp8x drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION descriptor. | CVSS3: 6.6 | 0% Низкий | около 4 лет назад | |
GHSA-xmxf-wjr9-rpwr In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-xmxf-f859-45ch Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-xmxf-9v5q-5mfw A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | CVSS3: 9.9 | 3% Низкий | больше 4 лет назад | |
GHSA-xmxc-mvx2-q963 On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled. | CVSS3: 5.9 | 1% Низкий | около 4 лет назад | |
GHSA-xmxc-8qjw-52gx Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. | 0% Низкий | около 4 лет назад | ||
GHSA-xmxc-2jc7-w66m In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xmx9-rjwq-m2x6 Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xmx9-mmqw-jcw6 The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file. | CVSS3: 5.5 | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу