Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-xw62-w8g4-hmhx

больше 3 лет назад

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw62-rx45-hvr3

4 месяца назад

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

EPSS: Низкий
github логотип

GHSA-xw62-fv8f-gc9h

больше 3 лет назад

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

EPSS: Низкий
github логотип

GHSA-xw5w-5r82-mf3j

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xw5v-rpqc-44jg

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw5r-6r86-qg74

почти 4 года назад

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

EPSS: Низкий
github логотип

GHSA-xw5r-2555-jwfv

больше 3 лет назад

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-xw5q-g62x-2qjc

7 месяцев назад

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw5q-6mjm-826q

почти 4 года назад

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xw5p-hw8j-xg4q

почти 3 года назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-xw5p-hw6r-2j98

больше 5 лет назад

Denial of service in fastify

EPSS: Низкий
github логотип

GHSA-xw5m-v83c-xc7p

больше 1 года назад

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw5m-hf8v-47cw

больше 1 года назад

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw5m-5vch-x6g5

около 2 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5j-gv2g-mjm2

почти 3 года назад

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

EPSS: Низкий
github логотип

GHSA-xw5j-8gp6-p2vj

больше 3 лет назад

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw5j-6ccc-rwh9

почти 4 года назад

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

EPSS: Низкий
github логотип

GHSA-xw5j-4h78-77h2

почти 4 года назад

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5h-h3cf-m4mx

почти 4 года назад

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

EPSS: Низкий
github логотип

GHSA-xw5h-8j92-59pp

больше 3 лет назад

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw62-w8g4-hmhx

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw62-rx45-hvr3

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

0%
Низкий
4 месяца назад
github логотип
GHSA-xw62-fv8f-gc9h

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5w-5r82-mf3j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-xw5v-rpqc-44jg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw5r-6r86-qg74

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xw5r-2555-jwfv

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5q-g62x-2qjc

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xw5q-6mjm-826q

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
52%
Средний
почти 3 года назад
github логотип
GHSA-xw5p-hw6r-2j98

Denial of service in fastify

0%
Низкий
больше 5 лет назад
github логотип
GHSA-xw5m-v83c-xc7p

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw5m-hf8v-47cw

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw5m-5vch-x6g5

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xw5j-gv2g-mjm2

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

почти 3 года назад
github логотип
GHSA-xw5j-8gp6-p2vj

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5j-6ccc-rwh9

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5j-4h78-77h2

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5h-h3cf-m4mx

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5h-8j92-59pp

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу