Количество 359 267
Количество 359 267
GHSA-xgv9-3cm6-qccq
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled.
GHSA-xgv8-xjgf-5cv2
Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via an invalid codec name.
GHSA-xgv8-vx7r-x752
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
GHSA-xgv8-r5gf-gjmj
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
GHSA-xgv8-hj8c-q8g5
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sonoma 14.8.3. An app may be able to access sensitive user data.
GHSA-xgv7-wccx-23jh
A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222073 was assigned to this vulnerability.
GHSA-xgv7-pqqh-h2w9
jruby-openssl gem for JRuby fails to do proper certificate validation
GHSA-xgv7-g262-2p9p
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Popliup allows PHP Local File Inclusion. This issue affects Popliup: from n/a through 1.1.1.
GHSA-xgv7-3hpx-fxm2
The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xgv6-w8v2-xv5f
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons for Elementor: from n/a through 2.2.0.
GHSA-xgv3-h5gf-43h8
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
GHSA-xgv3-98r5-2f57
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).
GHSA-xgv2-wjx4-5xp5
KENT-WEB Clip Board before 4.1 allows remote attackers to delete arbitrary files via unspecified vectors.
GHSA-xgv2-68c7-qh64
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.
GHSA-xgv2-5whc-jjqv
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
GHSA-xgv2-269m-88cx
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak.
GHSA-xgrx-xpv2-6vp4
Improper Authentication in Apache ActiveMQ
GHSA-xgrx-wvh6-5h6h
Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
GHSA-xgrv-mpr3-8pg9
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
GHSA-xgrq-rjm2-6qcr
The Dubstep Hero (aka com.electricpunch.dubstephero) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xgv9-3cm6-qccq The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of the 'firebase_sms_login' and 'firebase_sms_login_v2' functions. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-xgv8-xjgf-5cv2 Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via an invalid codec name. | 4% Низкий | больше 4 лет назад | ||
GHSA-xgv8-vx7r-x752 An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. | CVSS3: 6.3 | 0% Низкий | почти 3 года назад | |
GHSA-xgv8-r5gf-gjmj typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-xgv8-hj8c-q8g5 A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sonoma 14.8.3. An app may be able to access sensitive user data. | CVSS3: 5.5 | 3% Низкий | 8 месяцев назад | |
GHSA-xgv7-wccx-23jh A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222073 was assigned to this vulnerability. | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xgv7-pqqh-h2w9 jruby-openssl gem for JRuby fails to do proper certificate validation | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xgv7-g262-2p9p Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Popliup allows PHP Local File Inclusion. This issue affects Popliup: from n/a through 1.1.1. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-xgv7-3hpx-fxm2 The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 12 месяцев назад | |
GHSA-xgv6-w8v2-xv5f Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons for Elementor: from n/a through 2.2.0. | CVSS3: 5.9 | 0% Низкий | почти 2 года назад | |
GHSA-xgv3-h5gf-43h8 Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | CVSS3: 6.8 | 1% Низкий | почти 3 года назад | |
GHSA-xgv3-98r5-2f57 The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords). | 1% Низкий | больше 4 лет назад | ||
GHSA-xgv2-wjx4-5xp5 KENT-WEB Clip Board before 4.1 allows remote attackers to delete arbitrary files via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-xgv2-68c7-qh64 Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow. | CVSS3: 7.8 | 10% Средний | больше 4 лет назад | |
GHSA-xgv2-5whc-jjqv Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring. | 5% Низкий | больше 4 лет назад | ||
GHSA-xgv2-269m-88cx In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-multipart.c has a memory leak. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xgrx-xpv2-6vp4 Improper Authentication in Apache ActiveMQ | CVSS3: 5.9 | 5% Низкий | больше 4 лет назад | |
GHSA-xgrx-wvh6-5h6h Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0% Низкий | около 4 лет назад | ||
GHSA-xgrv-mpr3-8pg9 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell. | 4% Низкий | около 4 лет назад | ||
GHSA-xgrq-rjm2-6qcr The Dubstep Hero (aka com.electricpunch.dubstephero) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу