Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 410

Количество 290 410

github логотип

GHSA-xw9h-mxp6-gf7c

около 1 года назад

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw9h-8vfr-ppf5

больше 3 лет назад

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw9g-79q2-3vjw

больше 3 лет назад

Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw9f-xv55-jhcr

больше 3 лет назад

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

EPSS: Низкий
github логотип

GHSA-xw9f-r7rv-2cfw

больше 3 лет назад

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

EPSS: Низкий
github логотип

GHSA-xw9f-jjf6-qcrc

больше 3 лет назад

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.

EPSS: Низкий
github логотип

GHSA-xw9f-hwxg-fq6r

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw9c-r5pv-7f67

больше 3 лет назад

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

EPSS: Высокий
github логотип

GHSA-xw9c-qm7m-c9wc

больше 3 лет назад

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

EPSS: Низкий
github логотип

GHSA-xw9c-j6h9-9vjc

больше 3 лет назад

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

EPSS: Низкий
github логотип

GHSA-xw9c-79j7-p3p6

больше 3 лет назад

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw99-vmpf-qpg4

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

EPSS: Средний
github логотип

GHSA-xw99-jr69-5j43

больше 3 лет назад

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xw99-fqpg-v257

около 1 года назад

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw98-vm6c-57r4

больше 3 лет назад

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

EPSS: Низкий
github логотип

GHSA-xw98-6cfw-p3wh

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

EPSS: Средний
github логотип

GHSA-xw97-pjh6-x5h5

больше 3 лет назад

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

EPSS: Низкий
github логотип

GHSA-xw97-mfvw-wc3w

больше 1 года назад

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw97-6734-68pm

больше 3 лет назад

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

EPSS: Низкий
github логотип

GHSA-xw96-xcrg-p8w2

больше 3 лет назад

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw9h-mxp6-gf7c

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xw9h-8vfr-ppf5

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9g-79q2-3vjw

Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9f-xv55-jhcr

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9f-r7rv-2cfw

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9f-jjf6-qcrc

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9f-hwxg-fq6r

Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xw9c-r5pv-7f67

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

72%
Высокий
больше 3 лет назад
github логотип
GHSA-xw9c-qm7m-c9wc

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9c-j6h9-9vjc

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xw9c-79j7-p3p6

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw99-vmpf-qpg4

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

29%
Средний
больше 3 лет назад
github логотип
GHSA-xw99-jr69-5j43

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw99-fqpg-v257

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xw98-vm6c-57r4

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw98-6cfw-p3wh

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

31%
Средний
больше 3 лет назад
github логотип
GHSA-xw97-pjh6-x5h5

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw97-mfvw-wc3w

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
5%
Низкий
больше 1 года назад
github логотип
GHSA-xw97-6734-68pm

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw96-xcrg-p8w2

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу