Количество 358 043
Количество 358 043
GHSA-xm5f-366c-4fwr
In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
GHSA-xm5c-j9v6-7fmp
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force 124630.
GHSA-xm5c-f9c6-j794
Rejected reason: Not used
GHSA-xm5c-9c54-9j37
An issue was discovered in certain Apple products. macOS Server before 5.3 is affected. The issue involves the "Wiki Server" component. It allows remote attackers to enumerate user accounts via unspecified vectors.
GHSA-xm5c-4gf9-qf8c
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
GHSA-xm59-x79v-w7q2
The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over the user_id
GHSA-xm59-rqc7-hhvf
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
GHSA-xm59-jvxm-cp3v
mxGraph vulnerable to cross-site scripting in color field
GHSA-xm57-74q6-rw4j
In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or visit a page containing attack code, and send a request to the server (corresponding to the identity authentication information) as the victim without the victim's knowledge.
GHSA-xm4x-wc47-pq9m
Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
GHSA-xm4x-9c9x-4wcq
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
GHSA-xm4x-3r5h-vwfr
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.
GHSA-xm4w-v978-7gcx
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.
GHSA-xm4w-gp2v-m44c
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
GHSA-xm4r-pr55-hfw3
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
GHSA-xm4r-f4rc-2jjh
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
GHSA-xm4r-6vxg-m8fh
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
GHSA-xm4r-5rj9-2pg3
gratient 0.5 contains credential harvesting code
GHSA-xm4m-wpm4-fv32
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
GHSA-xm4m-v38w-7fr8
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cscode WooCommerce Estimate and Quote allows Reflected XSS. This issue affects WooCommerce Estimate and Quote: from n/a through 1.0.2.5.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xm5f-366c-4fwr In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges. | CVSS3: 9.8 | 1% Низкий | 12 месяцев назад | |
GHSA-xm5c-j9v6-7fmp IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force 124630. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-xm5c-f9c6-j794 Rejected reason: Not used | 6 месяцев назад | |||
GHSA-xm5c-9c54-9j37 An issue was discovered in certain Apple products. macOS Server before 5.3 is affected. The issue involves the "Wiki Server" component. It allows remote attackers to enumerate user accounts via unspecified vectors. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-xm5c-4gf9-qf8c Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
GHSA-xm59-x79v-w7q2 The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over the user_id | 1% Низкий | около 4 лет назад | ||
GHSA-xm59-rqc7-hhvf nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows | 0% Низкий | 8 месяцев назад | ||
GHSA-xm59-jvxm-cp3v mxGraph vulnerable to cross-site scripting in color field | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-xm57-74q6-rw4j In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or visit a page containing attack code, and send a request to the server (corresponding to the identity authentication information) as the victim without the victim's knowledge. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-xm4x-wc47-pq9m Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 1% Низкий | около 4 лет назад | ||
GHSA-xm4x-9c9x-4wcq The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xm4x-3r5h-vwfr Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password. | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
GHSA-xm4w-v978-7gcx In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-xm4w-gp2v-m44c SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-xm4r-pr55-hfw3 A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS. | 2% Низкий | около 4 лет назад | ||
GHSA-xm4r-f4rc-2jjh Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function. | 2% Низкий | больше 4 лет назад | ||
GHSA-xm4r-6vxg-m8fh Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 8.4 | 1% Низкий | около 1 года назад | |
GHSA-xm4r-5rj9-2pg3 gratient 0.5 contains credential harvesting code | CVSS3: 7.5 | почти 2 года назад | ||
GHSA-xm4m-wpm4-fv32 Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm4m-v38w-7fr8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cscode WooCommerce Estimate and Quote allows Reflected XSS. This issue affects WooCommerce Estimate and Quote: from n/a through 1.0.2.5. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу