Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 287 765

Количество 287 765

github логотип

GHSA-xxx5-wj7r-x3hv

больше 3 лет назад

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xxx5-7c7q-rc45

больше 1 года назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxx4-cx36-38r5

около 3 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxx4-63qf-8v87

почти 3 года назад

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxx4-4fcv-w56c

около 3 лет назад

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx3-q2f4-59h7

около 3 лет назад

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-xxx2-77cj-f65h

больше 3 лет назад

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

EPSS: Низкий
github логотип

GHSA-xxwx-xvv4-fvjw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

EPSS: Низкий
github логотип

GHSA-xxwx-qg6p-mx7w

5 месяцев назад

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxww-hv47-2ppx

около 3 лет назад

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

EPSS: Низкий
github логотип

GHSA-xxww-73xw-x3fj

около 2 лет назад

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxwv-v223-5w4w

больше 3 лет назад

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

EPSS: Низкий
github логотип

GHSA-xxwr-xc7w-gxgv

8 месяцев назад

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxwr-wv9g-7jw3

2 месяца назад

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxwr-whmf-f56p

больше 3 лет назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxwr-v6hc-32hm

почти 2 года назад

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxwq-xf8c-v665

больше 3 лет назад

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxwq-5h7x-mm4x

около 1 года назад

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxwm-xq6m-jwjx

больше 3 лет назад

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

EPSS: Низкий
github логотип

GHSA-xxwm-rvgr-f38w

около 3 лет назад

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxx5-wj7r-x3hv

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
43%
Средний
больше 3 лет назад
github логотип
GHSA-xxx5-7c7q-rc45

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxx4-63qf-8v87

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxx4-4fcv-w56c

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxx3-q2f4-59h7

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxx2-77cj-f65h

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwx-xvv4-fvjw

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwx-qg6p-mx7w

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxww-hv47-2ppx

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

2%
Низкий
около 3 лет назад
github логотип
GHSA-xxww-73xw-x3fj

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxwv-v223-5w4w

Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwr-xc7w-gxgv

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xxwr-wv9g-7jw3

The femanager TYPO3 extension allows Insecure Direct Object Reference

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xxwr-whmf-f56p

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress plugin) versions <= 1.5.2

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwr-v6hc-32hm

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxwq-xf8c-v665

A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwq-5h7x-mm4x

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-xxwm-xq6m-jwjx

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxwm-rvgr-f38w

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу