Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 803

Количество 289 803

github логотип

GHSA-xwgf-pv23-3mwx

около 3 лет назад

The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.

EPSS: Низкий
github логотип

GHSA-xwgc-vv45-5jgh

около 3 лет назад

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwgc-99jv-crpq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the URL submission form in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to inject arbitrary web script or HTML via an unspecified form for submitting URLs.

EPSS: Низкий
github логотип

GHSA-xwg8-9pgw-wh26

больше 3 лет назад

Multiple memory leaks in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allow remote attackers to cause a denial of service (memory consumption) via invalid LDAP requests.

EPSS: Низкий
github логотип

GHSA-xwg7-jq5f-xfcj

около 3 лет назад

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC-Q Series Q03UDECPU all versions, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU all versions, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwg7-27f3-h3r6

больше 3 лет назад

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

EPSS: Низкий
github логотип

GHSA-xwg5-v6xw-gqpc

больше 2 лет назад

A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various preconditions beyond the attackers control.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xwg4-93c6-3h42

почти 8 лет назад

Directory Traversal in send

EPSS: Низкий
github логотип

GHSA-xwg4-3m43-wmp8

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwg3-qrcg-w9x6

больше 4 лет назад

Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xwg3-q63r-8hgc

больше 3 лет назад

SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

EPSS: Низкий
github логотип

GHSA-xwg3-gjxh-c8pm

почти 5 лет назад

Malicious Package in ngx-context-menu

EPSS: Низкий
github логотип

GHSA-xwg2-xrcw-f6q6

больше 3 лет назад

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwg2-qc6c-7c3q

больше 3 лет назад

Fabric vulnerable to symlink attack on tmp files

EPSS: Низкий
github логотип

GHSA-xwfx-q77c-v4gg

почти 2 года назад

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwfx-mpm6-9wcg

больше 3 лет назад

Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

EPSS: Низкий
github логотип

GHSA-xwfx-cx94-457m

больше 3 лет назад

Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.

EPSS: Низкий
github логотип

GHSA-xwfx-786r-2r6f

около 3 лет назад

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwfw-xfh4-73wv

3 месяца назад

PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.

EPSS: Низкий
github логотип

GHSA-xwfw-c659-qjpj

больше 3 лет назад

ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwgf-pv23-3mwx

The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xwgc-vv45-5jgh

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwgc-99jv-crpq

Cross-site scripting (XSS) vulnerability in the URL submission form in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to inject arbitrary web script or HTML via an unspecified form for submitting URLs.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwg8-9pgw-wh26

Multiple memory leaks in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allow remote attackers to cause a denial of service (memory consumption) via invalid LDAP requests.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwg7-jq5f-xfcj

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC-Q Series Q03UDECPU all versions, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU all versions, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xwg7-27f3-h3r6

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwg5-v6xw-gqpc

A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various preconditions beyond the attackers control.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xwg4-93c6-3h42

Directory Traversal in send

5%
Низкий
почти 8 лет назад
github логотип
GHSA-xwg4-3m43-wmp8

Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xwg3-qrcg-w9x6

Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18

CVSS3: 4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xwg3-q63r-8hgc

SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xwg3-gjxh-c8pm

Malicious Package in ngx-context-menu

почти 5 лет назад
github логотип
GHSA-xwg2-xrcw-f6q6

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwg2-qc6c-7c3q

Fabric vulnerable to symlink attack on tmp files

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwfx-q77c-v4gg

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwfx-mpm6-9wcg

Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xwfx-cx94-457m

Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwfx-786r-2r6f

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwfw-xfh4-73wv

PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.

1%
Низкий
3 месяца назад
github логотип
GHSA-xwfw-c659-qjpj

ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу