Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 339

Количество 323 339

github логотип

GHSA-xwjh-cp99-cj8q

около 7 лет назад

Path Traversal in cordova-plugin-ionic-webview

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xwjg-xh72-4r4p

7 месяцев назад

A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xwjg-qxv6-28rv

больше 3 лет назад

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwjf-whc7-vgr2

почти 4 года назад

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

EPSS: Низкий
github логотип

GHSA-xwjf-v823-v896

почти 4 года назад

drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

EPSS: Низкий
github логотип

GHSA-xwjc-m85h-pr32

около 3 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwjc-4jxh-j5p8

почти 4 года назад

Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwj9-9vmw-m922

почти 4 года назад

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwj8-ppx9-j533

2 месяца назад

Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.

EPSS: Низкий
github логотип

GHSA-xwj7-29j7-rw76

почти 4 года назад

Cross site scripting in Elefant CMS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwj6-mjhc-r3jc

почти 4 года назад

Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

EPSS: Низкий
github логотип

GHSA-xwj6-f3wq-283g

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Twerdy Genesis Style Shortcodes allows DOM-Based XSS.This issue affects Genesis Style Shortcodes: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwj5-gj8r-8hr8

почти 4 года назад

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.

EPSS: Низкий
github логотип

GHSA-xwj5-fxxc-gf36

8 месяцев назад

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xwj5-5q25-vqmg

почти 2 года назад

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xwj3-m7ch-j848

почти 2 года назад

Memory corruption in HLOS while checking for the storage type.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xwj2-rcwr-xpcp

почти 2 года назад

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-22286.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xwj2-c9hw-p6p6

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: mm, slub: fix potential memoryleak in kmem_cache_open() In error path, the random_seq of slub cache might be leaked. Fix this by using __kmem_cache_release() to release all the relevant resources.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwhx-h3gq-62jp

почти 4 года назад

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-xwhx-6g69-79wc

больше 4 лет назад

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwjh-cp99-cj8q

Path Traversal in cordova-plugin-ionic-webview

CVSS3: 8.6
2%
Низкий
около 7 лет назад
github логотип
GHSA-xwjg-xh72-4r4p

A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xwjg-qxv6-28rv

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjf-whc7-vgr2

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xwjf-v823-v896

drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwjc-m85h-pr32

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwjc-4jxh-j5p8

Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwj9-9vmw-m922

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwj8-ppx9-j533

Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.

0%
Низкий
2 месяца назад
github логотип
GHSA-xwj7-29j7-rw76

Cross site scripting in Elefant CMS

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwj6-mjhc-r3jc

Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwj6-f3wq-283g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Twerdy Genesis Style Shortcodes allows DOM-Based XSS.This issue affects Genesis Style Shortcodes: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xwj5-gj8r-8hr8

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xwj5-fxxc-gf36

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xwj5-5q25-vqmg

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwj3-m7ch-j848

Memory corruption in HLOS while checking for the storage type.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwj2-rcwr-xpcp

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-22286.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwj2-c9hw-p6p6

In the Linux kernel, the following vulnerability has been resolved: mm, slub: fix potential memoryleak in kmem_cache_open() In error path, the random_seq of slub cache might be leaked. Fix this by using __kmem_cache_release() to release all the relevant resources.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwhx-h3gq-62jp

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

18%
Средний
почти 4 года назад
github логотип
GHSA-xwhx-6g69-79wc

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу