Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 419

Количество 323 419

github логотип

GHSA-xwcj-grfm-xm6q

больше 1 года назад

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwcj-5r58-c5mv

почти 4 года назад

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

EPSS: Низкий
github логотип

GHSA-xwch-xg3p-x5q5

почти 4 года назад

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

EPSS: Низкий
github логотип

GHSA-xwch-qpr5-vp62

почти 4 года назад

ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.

EPSS: Низкий
github логотип

GHSA-xwch-gx2x-qj27

почти 4 года назад

Remote Desktop Client Remote Code Execution Vulnerability.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xwch-5xjc-3j47

около 3 лет назад

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwcg-xmmg-hh8r

больше 1 года назад

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

CVSS3: 4.6
EPSS: Средний
github логотип

GHSA-xwcg-44xm-88h2

почти 4 года назад

The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xwcg-2ff3-38xv

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xwcf-mprh-wpvw

почти 3 года назад

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xwcc-7hmc-296q

почти 4 года назад

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving the base variable, leading to disclosure of the installation path, a different vulnerability than CVE-2011-2488.

EPSS: Низкий
github логотип

GHSA-xwcc-427v-vm78

почти 4 года назад

Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UN552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V964Q R2.000 and prior to it, C961Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it) allows an attacker to obtain root privileges and execute remote code by sending unintended parameters that contain specific characters in http request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwc9-vwhh-qfwc

около 1 месяца назад

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to /MailEssentials/pages/MailSecurity/advancedfiltering.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xwc9-h47c-3q6w

9 месяцев назад

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwc9-8235-mfg3

почти 4 года назад

The Echo News (aka com.solo.report) 1.10 application (beta) for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xwc8-wmf6-jq93

почти 4 года назад

Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and gain guest access.

EPSS: Низкий
github логотип

GHSA-xwc8-rf6m-xr86

больше 2 лет назад

hnswlib Double Free vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwc8-5q53-jg4p

почти 4 года назад

An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwc7-wmrh-7694

7 месяцев назад

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xwc7-pv4h-828f

около 4 лет назад

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwcj-grfm-xm6q

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwcj-5r58-c5mv

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xwch-xg3p-x5q5

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xwch-qpr5-vp62

ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xwch-gx2x-qj27

Remote Desktop Client Remote Code Execution Vulnerability.

CVSS3: 8.8
15%
Средний
почти 4 года назад
github логотип
GHSA-xwch-5xjc-3j47

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP user privileges.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwcg-xmmg-hh8r

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

CVSS3: 4.6
37%
Средний
больше 1 года назад
github логотип
GHSA-xwcg-44xm-88h2

The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.

CVSS3: 4.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwcg-2ff3-38xv

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-xwcf-mprh-wpvw

The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xwcc-7hmc-296q

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obtain sensitive information via vectors involving the base variable, leading to disclosure of the installation path, a different vulnerability than CVE-2011-2488.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwcc-427v-vm78

Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UN552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V964Q R2.000 and prior to it, C961Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it) allows an attacker to obtain root privileges and execute remote code by sending unintended parameters that contain specific characters in http request.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwc9-vwhh-qfwc

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$txtRuleName parameter to /MailEssentials/pages/MailSecurity/advancedfiltering.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xwc9-h47c-3q6w

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xwc9-8235-mfg3

The Echo News (aka com.solo.report) 1.10 application (beta) for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwc8-wmf6-jq93

Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and gain guest access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwc8-rf6m-xr86

hnswlib Double Free vulnerability

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xwc8-5q53-jg4p

An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwc7-wmrh-7694

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

CVSS3: 8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xwc7-pv4h-828f

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

CVSS3: 6.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу