Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-xwg4-93c6-3h42

почти 9 лет назад

Directory Traversal in send

EPSS: Низкий
github логотип

GHSA-xwg4-73v4-xw9w

18 дней назад

nanoid: Integer Overflow or Wraparound

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xwg4-3m43-wmp8

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwg3-qrcg-w9x6

больше 5 лет назад

Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xwg3-q63r-8hgc

больше 4 лет назад

SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

EPSS: Низкий
github логотип

GHSA-xwg3-gjxh-c8pm

около 6 лет назад

Malicious Package in ngx-context-menu

EPSS: Низкий
github логотип

GHSA-xwg2-xrcw-f6q6

больше 4 лет назад

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwg2-qc6c-7c3q

больше 4 лет назад

Fabric vulnerable to symlink attack on tmp files

EPSS: Низкий
github логотип

GHSA-xwfx-q77c-v4gg

почти 3 года назад

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwfx-mpm6-9wcg

больше 4 лет назад

Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

EPSS: Низкий
github логотип

GHSA-xwfx-cx94-457m

больше 4 лет назад

Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.

EPSS: Низкий
github логотип

GHSA-xwfx-786r-2r6f

больше 4 лет назад

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwfw-xfh4-73wv

больше 1 года назад

PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.

EPSS: Низкий
github логотип

GHSA-xwfw-c659-qjpj

больше 4 лет назад

ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.

EPSS: Низкий
github логотип

GHSA-xwfw-2pp3-pwh3

больше 3 лет назад

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xwfv-fh69-vfc3

больше 4 лет назад

IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.

EPSS: Низкий
github логотип

GHSA-xwfr-m7mh-vp2j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: set the right AMDGPU sg segment limitation The driver needs to set the correct max_segment_size; otherwise debug_dma_map_sg() will complain about the over-mapping of the AMDGPU sg length as following: WARNING: CPU: 6 PID: 1964 at kernel/dma/debug.c:1178 debug_dma_map_sg+0x2dc/0x370 [ 364.049444] Modules linked in: veth amdgpu(OE) amdxcp drm_exec gpu_sched drm_buddy drm_ttm_helper ttm(OE) drm_suballoc_helper drm_display_helper drm_kms_helper i2c_algo_bit rpcsec_gss_krb5 auth_rpcgss nfsv4 nfs lockd grace netfs xt_conntrack xt_MASQUERADE nf_conntrack_netlink xfrm_user xfrm_algo iptable_nat xt_addrtype iptable_filter br_netfilter nvme_fabrics overlay nfnetlink_cttimeout nfnetlink openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c bridge stp llc amd_atl intel_rapl_msr intel_rapl_common sunrpc sch_fq_codel snd_hda_codec_realtek snd_hda_codec_generic snd_hda_scodec_comp...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwfr-c9rv-m6pp

почти 2 года назад

A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwfq-89j4-72rw

больше 4 лет назад

DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration information via a direct request to configuration/general_configuration.html.

EPSS: Низкий
github логотип

GHSA-xwfq-4qhp-q48c

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3) lib/document.class.php or (4) lib/auth.inc.php.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwg4-93c6-3h42

Directory Traversal in send

4%
Низкий
почти 9 лет назад
github логотип
GHSA-xwg4-73v4-xw9w

nanoid: Integer Overflow or Wraparound

CVSS3: 7.4
0%
Низкий
18 дней назад
github логотип
GHSA-xwg4-3m43-wmp8

Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwg3-qrcg-w9x6

Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18

CVSS3: 4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-xwg3-q63r-8hgc

SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xwg3-gjxh-c8pm

Malicious Package in ngx-context-menu

около 6 лет назад
github логотип
GHSA-xwg2-xrcw-f6q6

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwg2-qc6c-7c3q

Fabric vulnerable to symlink attack on tmp files

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfx-q77c-v4gg

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xwfx-mpm6-9wcg

Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfx-cx94-457m

Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfx-786r-2r6f

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfw-xfh4-73wv

PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.

1%
Низкий
больше 1 года назад
github логотип
GHSA-xwfw-c659-qjpj

ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfw-2pp3-pwh3

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwfv-fh69-vfc3

IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfr-m7mh-vp2j

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: set the right AMDGPU sg segment limitation The driver needs to set the correct max_segment_size; otherwise debug_dma_map_sg() will complain about the over-mapping of the AMDGPU sg length as following: WARNING: CPU: 6 PID: 1964 at kernel/dma/debug.c:1178 debug_dma_map_sg+0x2dc/0x370 [ 364.049444] Modules linked in: veth amdgpu(OE) amdxcp drm_exec gpu_sched drm_buddy drm_ttm_helper ttm(OE) drm_suballoc_helper drm_display_helper drm_kms_helper i2c_algo_bit rpcsec_gss_krb5 auth_rpcgss nfsv4 nfs lockd grace netfs xt_conntrack xt_MASQUERADE nf_conntrack_netlink xfrm_user xfrm_algo iptable_nat xt_addrtype iptable_filter br_netfilter nvme_fabrics overlay nfnetlink_cttimeout nfnetlink openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 libcrc32c bridge stp llc amd_atl intel_rapl_msr intel_rapl_common sunrpc sch_fq_codel snd_hda_codec_realtek snd_hda_codec_generic snd_hda_scodec_comp...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwfr-c9rv-m6pp

A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

CVSS3: 7.5
2%
Низкий
почти 2 года назад
github логотип
GHSA-xwfq-89j4-72rw

DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration information via a direct request to configuration/general_configuration.html.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xwfq-4qhp-q48c

Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3) lib/document.class.php or (4) lib/auth.inc.php.

17%
Средний
больше 4 лет назад

Уязвимостей на страницу