Количество 358 234
Количество 358 234
GHSA-xj36-6xc6-8p9x
Jenkins Delphix Plugin has SSL/TLS certificate validation disabled by default
GHSA-xj35-x9j5-v64p
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
GHSA-xj35-wqmm-2cgp
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
GHSA-xj35-rhxx-w86c
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.
GHSA-xj35-g37r-frw9
Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.
GHSA-xj35-32mv-jpmp
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later
GHSA-xj34-w9xv-j378
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
GHSA-xj34-5mxh-m7xc
Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled.
GHSA-xj34-4cqx-j7ww
An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.
GHSA-xj33-wwm4-p8mw
In the Linux kernel, the following vulnerability has been resolved: bpf, s390: Fix potential memory leak about jit_data Make sure to free jit_data through kfree() in the error path.
GHSA-xj33-8r43-r227
Concrete CMS vulnerable to cross-site scripting in the text input field
GHSA-xj32-w24w-7c6q
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorrectly grants access if an 'AnonFile' query parameter containing exactly 256 characters is provided. While this flaw allows bypassing the intended authorization check, the actual security impact is negligible; the exposed resources are strictly limited to minified JavaScript and CSS files that contain no sensitive data and are already publicly accessible via a standard CDN.
GHSA-xj2x-rqf3-prc6
Rejected reason: Not used
GHSA-xj2x-h5m7-w8gv
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.
GHSA-xj2x-cvrp-j6cm
Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.
GHSA-xj2w-7m9r-98q7
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
GHSA-xj2w-28hg-8jjr
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
GHSA-xj2v-mgxg-mcm4
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while a malformed SSID is present.
GHSA-xj2v-h6gr-gp9q
The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
GHSA-xj2v-g4fg-gwmq
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xj36-6xc6-8p9x Jenkins Delphix Plugin has SSL/TLS certificate validation disabled by default | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xj35-x9j5-v64p Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | CVSS3: 5.5 | 3% Низкий | больше 4 лет назад | |
GHSA-xj35-wqmm-2cgp The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xj35-rhxx-w86c A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-xj35-g37r-frw9 Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-xj35-32mv-jpmp A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
GHSA-xj34-w9xv-j378 ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges. | CVSS3: 9.8 | 1% Низкий | 10 месяцев назад | |
GHSA-xj34-5mxh-m7xc Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled. | 3% Низкий | больше 4 лет назад | ||
GHSA-xj34-4cqx-j7ww An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xj33-wwm4-p8mw In the Linux kernel, the following vulnerability has been resolved: bpf, s390: Fix potential memory leak about jit_data Make sure to free jit_data through kfree() in the error path. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-xj33-8r43-r227 Concrete CMS vulnerable to cross-site scripting in the text input field | CVSS3: 4.2 | 1% Низкий | больше 3 лет назад | |
GHSA-xj32-w24w-7c6q An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorrectly grants access if an 'AnonFile' query parameter containing exactly 256 characters is provided. While this flaw allows bypassing the intended authorization check, the actual security impact is negligible; the exposed resources are strictly limited to minified JavaScript and CSS files that contain no sensitive data and are already publicly accessible via a standard CDN. | 0% Низкий | 2 месяца назад | ||
GHSA-xj2x-rqf3-prc6 Rejected reason: Not used | 11 месяцев назад | |||
GHSA-xj2x-h5m7-w8gv An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible. | 1% Низкий | больше 4 лет назад | ||
GHSA-xj2x-cvrp-j6cm Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp. | 1% Низкий | больше 4 лет назад | ||
GHSA-xj2w-7m9r-98q7 In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page | 1% Низкий | около 4 лет назад | ||
GHSA-xj2w-28hg-8jjr IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040. | 1% Низкий | больше 4 лет назад | ||
GHSA-xj2v-mgxg-mcm4 ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while a malformed SSID is present. | CVSS3: 4.5 | 0% Низкий | 4 месяца назад | |
GHSA-xj2v-h6gr-gp9q The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | CVSS3: 4.4 | 0% Низкий | 4 месяца назад | |
GHSA-xj2v-g4fg-gwmq An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system. | CVSS3: 4.9 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу