Количество 358 234
Количество 358 234
GHSA-xj72-wvfv-8985
vm2 Sandbox Escape vulnerability
GHSA-xj72-m52w-529q
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
GHSA-xj72-8cc7-64m7
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-xj72-54x6-jmcv
Microsoft SQL Server Remote Code Execution Vulnerability
GHSA-xj72-54ch-xhfx
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.
GHSA-xj6x-54xc-64j5
An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.
GHSA-xj6x-4fwp-9v78
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.
GHSA-xj6v-rj9r-jrjq
The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xj6v-gwfp-883r
Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-xj6v-gr3v-5fpq
A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xj6v-38m3-64p9
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xj6v-33q6-wvxj
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
GHSA-xj6r-wv4q-mrm6
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
GHSA-xj6r-wgr5-8rxc
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
GHSA-xj6r-gmjj-ghvc
Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.
GHSA-xj6r-2jpm-qvxp
Code injection issue for java-spring-cloud-stream-template
GHSA-xj6q-9hx8-mm7f
Directory Traversal in liuyaserver
GHSA-xj6q-8x83-jv6g
Axios: Prototype pollution auth subfields can inject Basic auth
GHSA-xj6q-3qm4-vg6w
An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1516.
GHSA-xj6m-g8xh-h3xc
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xj72-wvfv-8985 vm2 Sandbox Escape vulnerability | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад | |
GHSA-xj72-m52w-529q Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xj72-8cc7-64m7 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | 6 месяцев назад | |||
GHSA-xj72-54x6-jmcv Microsoft SQL Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-xj72-54ch-xhfx Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-xj6x-54xc-64j5 An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application. | CVSS3: 5.7 | 0% Низкий | 4 дня назад | |
GHSA-xj6x-4fwp-9v78 Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution. | CVSS3: 7.8 | 19% Средний | около 4 лет назад | |
GHSA-xj6v-rj9r-jrjq The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 2 лет назад | |
GHSA-xj6v-gwfp-883r Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xj6v-gr3v-5fpq A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | 11 месяцев назад | |
GHSA-xj6v-38m3-64p9 Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-xj6v-33q6-wvxj Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | CVSS3: 9.8 | 0% Низкий | 25 дней назад | |
GHSA-xj6r-wv4q-mrm6 In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. | 1% Низкий | больше 4 лет назад | ||
GHSA-xj6r-wgr5-8rxc In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | CVSS3: 4.1 | 1% Низкий | больше 1 года назад | |
GHSA-xj6r-gmjj-ghvc Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter. | CVSS3: 7.2 | 2% Низкий | больше 4 лет назад | |
GHSA-xj6r-2jpm-qvxp Code injection issue for java-spring-cloud-stream-template | CVSS3: 8.7 | 1% Низкий | почти 5 лет назад | |
GHSA-xj6q-9hx8-mm7f Directory Traversal in liuyaserver | 2% Низкий | почти 6 лет назад | ||
GHSA-xj6q-8x83-jv6g Axios: Prototype pollution auth subfields can inject Basic auth | 0% Низкий | 26 дней назад | ||
GHSA-xj6q-3qm4-vg6w An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1516. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-xj6m-g8xh-h3xc In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу