Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 267

Количество 322 267

github логотип

GHSA-xxx9-3xcr-gjj3

почти 4 года назад

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx8-w7mj-hmgq

почти 4 года назад

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxx7-j74c-5xrg

14 дней назад

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx6-f4cg-v662

больше 3 лет назад

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx5-wj7r-x3hv

около 4 лет назад

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xxx5-7c7q-rc45

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxx4-cx36-38r5

почти 4 года назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxx4-63qf-8v87

больше 3 лет назад

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxx4-4fcv-w56c

почти 4 года назад

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx3-q2f4-59h7

почти 4 года назад

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-xxx3-p74m-7mjp

5 месяцев назад

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxx2-77cj-f65h

почти 4 года назад

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

EPSS: Низкий
github логотип

GHSA-xxwx-xvv4-fvjw

почти 4 года назад

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

EPSS: Низкий
github логотип

GHSA-xxwx-qg6p-mx7w

около 1 года назад

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxww-hv47-2ppx

почти 4 года назад

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

EPSS: Низкий
github логотип

GHSA-xxww-73xw-x3fj

почти 3 года назад

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxwv-v223-5w4w

почти 4 года назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

EPSS: Низкий
github логотип

GHSA-xxwr-xc7w-gxgv

больше 1 года назад

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxwr-wv9g-7jw3

10 месяцев назад

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxwr-whmf-f56p

почти 4 года назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
почти 4 года назад
github логотип
GHSA-xxx8-w7mj-hmgq

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxx7-j74c-5xrg

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
0%
Низкий
14 дней назад
github логотип
GHSA-xxx6-f4cg-v662

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxx5-wj7r-x3hv

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
36%
Средний
около 4 лет назад
github логотип
GHSA-xxx5-7c7q-rc45

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxx4-63qf-8v87

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxx4-4fcv-w56c

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxx3-q2f4-59h7

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxx3-p74m-7mjp

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxx2-77cj-f65h

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

5%
Низкий
почти 4 года назад
github логотип
GHSA-xxwx-xvv4-fvjw

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxwx-qg6p-mx7w

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xxww-hv47-2ppx

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xxww-73xw-x3fj

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxwv-v223-5w4w

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xxwr-xc7w-gxgv

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-xxwr-wv9g-7jw3

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxwr-whmf-f56p

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу