Количество 359 567
Количество 359 567
GHSA-xgm3-c7j6-6pf4
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xgm3-c263-cjqp
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.
GHSA-xgm2-cpgm-525v
ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting.
GHSA-xgm2-c6j6-q2v6
The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
GHSA-xgm2-9pcq-75hg
Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.
GHSA-xgm2-6pvq-chh4
MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.
GHSA-xgm2-5f3f-mvvc
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
GHSA-xgjx-9p2f-rwjw
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-xgjx-96v4-mqxx
Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection
GHSA-xgjw-vr88-rxg7
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
GHSA-xgjw-pm74-86q4
sigstore-js has Insufficient Verification of Data Authenticity
GHSA-xgjv-9929-vw26
Loftware Spectrum through 4.6 has unprotected JMX Registry.
GHSA-xgjv-6gmp-cprw
PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.
GHSA-xgjv-46p6-hwgv
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.
GHSA-xgjq-gf22-rvwq
The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
GHSA-xgjq-frv6-vjfh
A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xgjp-hj9v-xx75
A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-xgjm-w63f-4hqq
Windows Compressed Folder Tampering Vulnerability
GHSA-xgjm-4322-4ccq
CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
GHSA-xgjj-x9g2-jxw7
Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xgm3-c7j6-6pf4 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 8 месяцев назад | |||
GHSA-xgm3-c263-cjqp Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities. | 2% Низкий | около 4 лет назад | ||
GHSA-xgm2-cpgm-525v ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting. | CVSS3: 2 | 0% Низкий | больше 2 лет назад | |
GHSA-xgm2-c6j6-q2v6 The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-xgm2-9pcq-75hg Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2. | CVSS3: 9.1 | 1% Низкий | больше 2 лет назад | |
GHSA-xgm2-6pvq-chh4 MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-xgm2-5f3f-mvvc Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication | CVSS3: 4.8 | 0% Низкий | 29 дней назад | |
GHSA-xgjx-9p2f-rwjw Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-xgjx-96v4-mqxx Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox Protection | CVSS3: 7.3 | 2% Низкий | больше 4 лет назад | |
GHSA-xgjw-vr88-rxg7 Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xgjw-pm74-86q4 sigstore-js has Insufficient Verification of Data Authenticity | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-xgjv-9929-vw26 Loftware Spectrum through 4.6 has unprotected JMX Registry. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-xgjv-6gmp-cprw PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xgjv-46p6-hwgv GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads. | CVSS3: 7.5 | 1% Низкий | 10 месяцев назад | |
GHSA-xgjq-gf22-rvwq The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | CVSS3: 6.5 | 0% Низкий | 13 дней назад | |
GHSA-xgjq-frv6-vjfh A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.3 | 0% Низкий | 11 месяцев назад | |
GHSA-xgjp-hj9v-xx75 A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-xgjm-w63f-4hqq Windows Compressed Folder Tampering Vulnerability | CVSS3: 6.5 | 30% Средний | больше 2 лет назад | |
GHSA-xgjm-4322-4ccq CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
GHSA-xgjj-x9g2-jxw7 Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3. | CVSS3: 10 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу