Количество 357 271
Количество 357 271
GHSA-xmwc-2xfr-rrcr
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.
GHSA-xmw9-q7x9-j5qc
Unbounded connection acceptance leads to file handle exhaustion
GHSA-xmw9-gg4q-2f2x
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
GHSA-xmw9-879h-j6mq
Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.
GHSA-xmw9-6v8p-w6jg
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
GHSA-xmw9-6r43-x9ww
SiYuan has directory traversal within its publishing service
GHSA-xmw8-pxhc-cq64
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras.
GHSA-xmw7-wmp8-hj98
Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.
GHSA-xmw7-pfh7-ccxp
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
GHSA-xmw7-848p-p95w
Airbnb Knowledge Repo XSS In Comments
GHSA-xmw5-w4c2-cp2g
SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
GHSA-xmw5-45v9-pxqx
XSS vulnerability in Jenkins TICS Plugin
GHSA-xmw4-wxv9-hm5g
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
GHSA-xmw3-64p4-g77h
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.
GHSA-xmw2-mw3c-793w
Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.
GHSA-xmw2-h4mh-h75v
Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
GHSA-xmw2-9pgq-w58j
The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.
GHSA-xmw2-9fv2-vx29
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.
GHSA-xmw2-8pp9-3q4c
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-xmw2-2pgj-jq4h
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xmwc-2xfr-rrcr WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site. | 1% Низкий | около 4 лет назад | ||
GHSA-xmw9-q7x9-j5qc Unbounded connection acceptance leads to file handle exhaustion | CVSS3: 7.5 | 2% Низкий | больше 5 лет назад | |
GHSA-xmw9-gg4q-2f2x Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | 17% Средний | больше 4 лет назад | ||
GHSA-xmw9-879h-j6mq Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command. | 3% Низкий | больше 4 лет назад | ||
GHSA-xmw9-6v8p-w6jg Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue." | 1% Низкий | около 4 лет назад | ||
GHSA-xmw9-6r43-x9ww SiYuan has directory traversal within its publishing service | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
GHSA-xmw8-pxhc-cq64 A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras. | 0% Низкий | около 2 месяцев назад | ||
GHSA-xmw7-wmp8-hj98 Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-xmw7-pfh7-ccxp The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xmw7-848p-p95w Airbnb Knowledge Repo XSS In Comments | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xmw5-w4c2-cp2g SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication. | CVSS3: 8.1 | 0% Низкий | 26 дней назад | |
GHSA-xmw5-45v9-pxqx XSS vulnerability in Jenkins TICS Plugin | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xmw4-wxv9-hm5g Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
GHSA-xmw3-64p4-g77h Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior. | CVSS3: 9.8 | 2% Низкий | 6 месяцев назад | |
GHSA-xmw2-mw3c-793w Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination. | 1% Низкий | больше 4 лет назад | ||
GHSA-xmw2-h4mh-h75v Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-xmw2-9pgq-w58j The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet. | 2% Низкий | около 4 лет назад | ||
GHSA-xmw2-9fv2-vx29 Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xmw2-8pp9-3q4c SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xmw2-2pgj-jq4h Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу