Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-xvjm-g277-p3fj

больше 3 лет назад

SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

EPSS: Низкий
github логотип

GHSA-xvjm-fvxx-q3hv

больше 4 лет назад

CHECK-fail due to integer overflow

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xvjm-5f8w-rrvc

больше 3 лет назад

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

EPSS: Низкий
github логотип

GHSA-xvjj-mhxv-ccr9

больше 3 лет назад

Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.

EPSS: Низкий
github логотип

GHSA-xvjj-hpv8-263f

больше 3 лет назад

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

EPSS: Низкий
github логотип

GHSA-xvjj-gv4g-2h8h

больше 3 лет назад

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 750m11ac wireless router via the HTTP request parameter in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.

EPSS: Средний
github логотип

GHSA-xvjg-xxqh-hg7q

3 месяца назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvjg-4qjv-mmc7

больше 1 года назад

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-xvjf-wwff-cwgg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvjf-ppxc-mvvq

почти 3 года назад

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvjf-5mpw-35xg

больше 3 лет назад

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvjf-3q8p-7pjv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

EPSS: Низкий
github логотип

GHSA-xvjf-394g-phrr

больше 3 лет назад

TeamPass Improper Privilege Management

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xvjc-64pg-p82q

больше 2 лет назад

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_upass' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvj9-g93g-8ggp

больше 3 лет назад

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvj9-4p6c-c3xm

больше 2 лет назад

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xvj8-fgfh-f3gx

4 месяца назад

Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Request Forgery.This issue affects Slider Templates: from n/a through <= 1.0.3.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xvj7-rgf2-85f2

почти 4 года назад

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

EPSS: Низкий
github логотип

GHSA-xvj7-6x37-qqfw

12 месяцев назад

The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xvj5-gjgh-q624

почти 4 года назад

PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvjm-g277-p3fj

SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjm-fvxx-q3hv

CHECK-fail due to integer overflow

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvjm-5f8w-rrvc

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjj-mhxv-ccr9

Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjj-hpv8-263f

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjj-gv4g-2h8h

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 750m11ac wireless router via the HTTP request parameter in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.

16%
Средний
больше 3 лет назад
github логотип
GHSA-xvjg-xxqh-hg7q

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xvjg-4qjv-mmc7

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.

CVSS3: 7.2
10%
Средний
больше 1 года назад
github логотип
GHSA-xvjf-wwff-cwgg

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjf-ppxc-mvvq

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xvjf-5mpw-35xg

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjf-3q8p-7pjv

Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjf-394g-phrr

TeamPass Improper Privilege Management

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjc-64pg-p82q

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_upass' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-xvj9-g93g-8ggp

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvj9-4p6c-c3xm

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvj8-fgfh-f3gx

Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Request Forgery.This issue affects Slider Templates: from n/a through <= 1.0.3.

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-xvj7-rgf2-85f2

The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xvj7-6x37-qqfw

The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-xvj5-gjgh-q624

PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.

12%
Средний
почти 4 года назад

Уязвимостей на страницу