Количество 360 872
Количество 360 872
GHSA-xg75-68x3-7p3q
Apache Struts vulnerable to possible DoS attack when using URLValidator
GHSA-xg75-35c7-jmgx
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.
GHSA-xg75-3277-gvvj
Directory Traversal in serve
GHSA-xg73-94fp-g449
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
GHSA-xg73-5hqj-7hwg
A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xg72-j993-8h8h
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-xg72-j456-mcj9
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
GHSA-xg72-6c83-ghh4
Microweber Stored Cross-site Scripting before v1.2.20
GHSA-xg6x-xg63-gmxc
In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path.
GHSA-xg6x-r7hq-2gx8
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.
GHSA-xg6x-h9c9-2m83
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
GHSA-xg6w-w34w-wcwm
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
GHSA-xg6w-qq7g-f5fh
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
GHSA-xg6w-h55h-j5qh
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.
GHSA-xg6w-8fxx-mqf6
A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223411.
GHSA-xg6v-xh9g-65cv
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
GHSA-xg6v-vr2f-h5xx
Improper memory initialization in Platform Sample/Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially enable an escalation of privilege via local access.
GHSA-xg6r-jcjj-j993
cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).
GHSA-xg6r-cjq3-qmj5
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
GHSA-xg6r-c3f5-m35h
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xg75-68x3-7p3q Apache Struts vulnerable to possible DoS attack when using URLValidator | CVSS3: 5.3 | 10% Средний | больше 4 лет назад | |
GHSA-xg75-35c7-jmgx Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php. | CVSS3: 7.2 | 1% Низкий | больше 3 лет назад | |
GHSA-xg75-3277-gvvj Directory Traversal in serve | CVSS3: 7.5 | 2% Низкий | больше 7 лет назад | |
GHSA-xg73-94fp-g449 mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs | CVSS3: 9.8 | 70% Средний | больше 3 лет назад | |
GHSA-xg73-5hqj-7hwg A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-xg72-j993-8h8h The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
GHSA-xg72-j456-mcj9 Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100. | CVSS3: 5.6 | 0% Низкий | больше 1 года назад | |
GHSA-xg72-6c83-ghh4 Microweber Stored Cross-site Scripting before v1.2.20 | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-xg6x-xg63-gmxc In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry even when the lookup resolves to an error route. If dst->error is set, xfrm6_rcv_encap() drops the skb without attaching the dst to the skb and without releasing the reference returned by the lookup. Repeated packets hitting this path therefore leak dst entries. Release the dst before jumping to the drop path. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
GHSA-xg6x-r7hq-2gx8 Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS. | 4% Низкий | больше 4 лет назад | ||
GHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache) | 5 месяцев назад | |||
GHSA-xg6w-w34w-wcwm IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie. | CVSS3: 3.1 | 1% Низкий | больше 4 лет назад | |
GHSA-xg6w-qq7g-f5fh Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xg6w-h55h-j5qh IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file. | 0% Низкий | больше 4 лет назад | ||
GHSA-xg6w-8fxx-mqf6 A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ecommerce/admin/category/controller.php of the component Category Name Handler. The manipulation of the argument CATEGORY leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223411. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xg6v-xh9g-65cv On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-xg6v-vr2f-h5xx Improper memory initialization in Platform Sample/Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially enable an escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | больше 4 лет назад | |
GHSA-xg6r-jcjj-j993 cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). | 2% Низкий | около 4 лет назад | ||
GHSA-xg6r-cjq3-qmj5 HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-xg6r-c3f5-m35h Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513. | 8% Низкий | больше 4 лет назад |
Уязвимостей на страницу