Количество 359 267
Количество 359 267
GHSA-xh3c-jh29-g5wj
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
GHSA-xh3c-fg2p-f6rr
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
GHSA-xh3c-6gcq-g4rv
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
GHSA-xh3c-49q5-vp78
lunary-ai/lunary version 1.0.0 is vulnerable to unauthorized evaluation creation due to missing server-side checks for user account status during evaluation creation. While the web UI restricts evaluation creation to paid accounts, the server-side API endpoint '/v1/evaluations' does not verify if the user has a paid account, allowing users with free or self-hosted accounts to create unlimited evaluations without upgrading their account. This vulnerability is due to the lack of account status validation in the evaluation creation process.
GHSA-xh39-w65m-vxrw
A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can send a specific .ISO file to trigger this vulnerability.
GHSA-xh38-hrrg-8cjv
A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later
GHSA-xh37-q5jv-v72j
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rafel Sansó Gmap Point List allows Stored XSS.This issue affects Gmap Point List: from n/a through 1.1.2.
GHSA-xh37-7fm5-6m6h
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
GHSA-xh36-r8rr-4pmg
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
GHSA-xh36-jjpq-3cmr
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.
GHSA-xh36-cr78-92jc
A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
GHSA-xh36-8q3w-g243
A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on.
GHSA-xh35-w7wg-95v3
XWiki has no right protection on rollback action
GHSA-xh35-9rm8-7v5q
samurai 1.2 has a NULL pointer dereference in writefile() in util.c via a crafted build file.
GHSA-xh35-43pp-33v2
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
GHSA-xh34-wfjw-6gjr
Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access.
GHSA-xh34-jr4v-w5wr
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
GHSA-xh33-x4fq-3r2h
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
GHSA-xh33-q298-mqqf
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component TRACE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-xh33-9j66-fv2x
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh3c-jh29-g5wj An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub. | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-xh3c-fg2p-f6rr ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-xh3c-6gcq-g4rv multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-xh3c-49q5-vp78 lunary-ai/lunary version 1.0.0 is vulnerable to unauthorized evaluation creation due to missing server-side checks for user account status during evaluation creation. While the web UI restricts evaluation creation to paid accounts, the server-side API endpoint '/v1/evaluations' does not verify if the user has a paid account, allowing users with free or self-hosted accounts to create unlimited evaluations without upgrading their account. This vulnerability is due to the lack of account status validation in the evaluation creation process. | CVSS3: 5.3 | больше 2 лет назад | ||
GHSA-xh39-w65m-vxrw A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can send a specific .ISO file to trigger this vulnerability. | CVSS3: 7.8 | 9% Низкий | больше 4 лет назад | |
GHSA-xh38-hrrg-8cjv A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTS hero h5.1.3.2578 build 20231110 and later | CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | |
GHSA-xh37-q5jv-v72j Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rafel Sansó Gmap Point List allows Stored XSS.This issue affects Gmap Point List: from n/a through 1.1.2. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-xh37-7fm5-6m6h Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-xh36-r8rr-4pmg An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI. | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
GHSA-xh36-jjpq-3cmr The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
GHSA-xh36-cr78-92jc A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | 1% Низкий | около 4 лет назад | ||
GHSA-xh36-8q3w-g243 A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on. | CVSS3: 7 | 0% Низкий | больше 2 лет назад | |
GHSA-xh35-w7wg-95v3 XWiki has no right protection on rollback action | CVSS3: 8 | 1% Низкий | больше 2 лет назад | |
GHSA-xh35-9rm8-7v5q samurai 1.2 has a NULL pointer dereference in writefile() in util.c via a crafted build file. | 1% Низкий | около 4 лет назад | ||
GHSA-xh35-43pp-33v2 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1. | CVSS3: 3.1 | 0% Низкий | 7 месяцев назад | |
GHSA-xh34-wfjw-6gjr Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access. | 0% Низкий | около 4 лет назад | ||
GHSA-xh34-jr4v-w5wr SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-xh33-x4fq-3r2h A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh33-q298-mqqf A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component TRACE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-xh33-9j66-fv2x The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | 18% Средний | около 4 лет назад |
Уязвимостей на страницу