Количество 359 267
Количество 359 267
GHSA-xh6j-pwvm-gcgm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0.
GHSA-xh6j-j322-g8m3
, aka 'Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability'.
GHSA-xh6j-gj5f-hrpp
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
GHSA-xh6g-prc3-64gx
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.
GHSA-xh6g-hp9w-9662
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
GHSA-xh69-9jx5-xgph
Windows Active Directory Domain Services API Denial of Service Vulnerability
GHSA-xh69-9chv-wc4v
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Földesi, Mihály Széchenyi 2020 Logo allows PHP Local File Inclusion. This issue affects Széchenyi 2020 Logo: from n/a through 1.1.
GHSA-xh69-987w-hrp8
resolv vulnerable to DoS via insufficient DNS domain name length validation
GHSA-xh68-hfp5-5x5m
daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
GHSA-xh68-gx4p-f4cx
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.
GHSA-xh68-c6f3-2hjc
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.
GHSA-xh67-rj29-r547
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
GHSA-xh67-8c9c-jwgx
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.
GHSA-xh66-6mj6-94rg
Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
GHSA-xh66-6hj7-62mw
An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory, aka 'Active Directory Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0856.
GHSA-xh65-fv62-6rcf
Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02.
GHSA-xh64-rxr5-8ggh
The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
GHSA-xh64-rg4w-vmpm
Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.
GHSA-xh64-jjg2-744m
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
GHSA-xh64-ffcx-p82v
Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh6j-pwvm-gcgm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0. | CVSS3: 5.8 | 0% Низкий | больше 1 года назад | |
GHSA-xh6j-j322-g8m3 , aka 'Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability'. | CVSS3: 7.8 | 4% Низкий | около 4 лет назад | |
GHSA-xh6j-gj5f-hrpp In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution. | CVSS3: 9.8 | 53% Средний | около 4 лет назад | |
GHSA-xh6g-prc3-64gx Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480. | 2% Низкий | больше 4 лет назад | ||
GHSA-xh6g-hp9w-9662 ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network. | 1% Низкий | около 4 лет назад | ||
GHSA-xh69-9jx5-xgph Windows Active Directory Domain Services API Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
GHSA-xh69-9chv-wc4v Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Földesi, Mihály Széchenyi 2020 Logo allows PHP Local File Inclusion. This issue affects Széchenyi 2020 Logo: from n/a through 1.1. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-xh69-987w-hrp8 resolv vulnerable to DoS via insufficient DNS domain name length validation | CVSS3: 5.3 | 1% Низкий | около 1 года назад | |
GHSA-xh68-hfp5-5x5m daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators | CVSS3: 3.7 | 0% Низкий | 2 месяца назад | |
GHSA-xh68-gx4p-f4cx A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh68-c6f3-2hjc A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data. | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
GHSA-xh67-rj29-r547 Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh67-8c9c-jwgx Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-xh66-6mj6-94rg Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xh66-6hj7-62mw An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory, aka 'Active Directory Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0856. | CVSS3: 6.5 | 4% Низкий | около 4 лет назад | |
GHSA-xh65-fv62-6rcf Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02. | 4% Низкий | больше 4 лет назад | ||
GHSA-xh64-rxr5-8ggh The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances. | 0% Низкий | около 1 месяца назад | ||
GHSA-xh64-rg4w-vmpm Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-xh64-jjg2-744m Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump. | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-xh64-ffcx-p82v Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу