Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xw5q-6mjm-826q

почти 4 года назад

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xw5p-hw8j-xg4q

около 3 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-xw5p-hw6r-2j98

больше 5 лет назад

Denial of service in fastify

EPSS: Низкий
github логотип

GHSA-xw5m-v83c-xc7p

больше 1 года назад

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw5m-hf8v-47cw

почти 2 года назад

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw5m-5vch-x6g5

4 месяца назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5j-gv2g-mjm2

около 3 лет назад

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

EPSS: Низкий
github логотип

GHSA-xw5j-8gp6-p2vj

почти 4 года назад

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw5j-6ccc-rwh9

почти 4 года назад

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

EPSS: Низкий
github логотип

GHSA-xw5j-4h78-77h2

около 4 лет назад

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5h-h3cf-m4mx

почти 4 года назад

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

EPSS: Низкий
github логотип

GHSA-xw5h-8j92-59pp

больше 3 лет назад

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw5g-qgw7-x534

почти 4 года назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw5g-39g7-vh7x

больше 3 лет назад

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xw5f-m9q2-678f

почти 4 года назад

Microsoft SharePoint Denial of Service Update

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xw5f-g937-wgm2

почти 4 года назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xw5f-2w3q-6c92

почти 4 года назад

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xw5c-xwc7-95gf

около 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw59-4mp5-9chf

почти 4 года назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xw58-crph-crhm

больше 2 лет назад

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw5q-6mjm-826q

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
49%
Средний
около 3 лет назад
github логотип
GHSA-xw5p-hw6r-2j98

Denial of service in fastify

0%
Низкий
больше 5 лет назад
github логотип
GHSA-xw5m-v83c-xc7p

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw5m-hf8v-47cw

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xw5m-5vch-x6g5

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-xw5j-gv2g-mjm2

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

около 3 лет назад
github логотип
GHSA-xw5j-8gp6-p2vj

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw5j-6ccc-rwh9

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5j-4h78-77h2

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xw5h-h3cf-m4mx

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5h-8j92-59pp

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5g-qgw7-x534

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5g-39g7-vh7x

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5f-m9q2-678f

Microsoft SharePoint Denial of Service Update

CVSS3: 5
2%
Низкий
почти 4 года назад
github логотип
GHSA-xw5f-g937-wgm2

ChakraCore RCE Vulnerability

CVSS3: 7.5
24%
Средний
почти 4 года назад
github логотип
GHSA-xw5f-2w3q-6c92

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
3%
Низкий
почти 4 года назад
github логотип
GHSA-xw5c-xwc7-95gf

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
8%
Низкий
около 3 лет назад
github логотип
GHSA-xw59-4mp5-9chf

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
6%
Низкий
почти 4 года назад
github логотип
GHSA-xw58-crph-crhm

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу