Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-xv29-9jgf-xj5j

больше 3 лет назад

Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv27-hp74-6hr9

почти 2 года назад

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xv26-933m-66h2

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the style attribute of FileAttachment annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5026.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv26-8c3v-gqcv

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ireca allows PHP Local File Inclusion. This issue affects Ireca: from n/a through 1.8.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv26-38rg-x8c2

3 месяца назад

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv22-g7rf-h2p4

больше 3 лет назад

Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.

EPSS: Низкий
github логотип

GHSA-xrxx-94c8-w7rw

почти 3 года назад

In PVRSRVBridgeRGXTDMSubmitTransfer of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-270397970

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrxv-q9j2-38v5

4 месяца назад

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

EPSS: Низкий
github логотип

GHSA-xrxv-pj5w-gmxx

больше 3 лет назад

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xrxr-xwxg-4g42

9 месяцев назад

A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrxr-x757-5v8c

9 месяцев назад

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrxr-vcvh-gm7h

почти 4 года назад

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrxr-87wr-8j4m

больше 2 лет назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrxr-6vrf-4m23

около 3 лет назад

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrxq-x8xp-9x7h

9 месяцев назад

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrxq-r6x5-h4vf

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Weil WP Order By allows Reflected XSS.This issue affects WP Order By: from n/a through 1.4.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrxq-p636-j73q

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean up the allocated memory for the management command.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xrxq-fc9m-fg9v

больше 3 лет назад

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.

EPSS: Низкий
github логотип

GHSA-xrxp-wj2g-wrxj

почти 3 года назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrxm-mvqm-r553

больше 3 лет назад

Helm Path Traversal

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv29-9jgf-xj5j

Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv27-hp74-6hr9

SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv26-933m-66h2

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the style attribute of FileAttachment annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5026.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv26-8c3v-gqcv

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ireca allows PHP Local File Inclusion. This issue affects Ireca: from n/a through 1.8.5.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xv26-38rg-x8c2

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xv22-g7rf-h2p4

Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxx-94c8-w7rw

In PVRSRVBridgeRGXTDMSubmitTransfer of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-270397970

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrxv-q9j2-38v5

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

0%
Низкий
4 месяца назад
github логотип
GHSA-xrxv-pj5w-gmxx

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxr-xwxg-4g42

A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrxr-x757-5v8c

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrxr-vcvh-gm7h

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrxr-87wr-8j4m

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrxr-6vrf-4m23

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVSS3: 5.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrxq-x8xp-9x7h

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrxq-r6x5-h4vf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Weil WP Order By allows Reflected XSS.This issue affects WP Order By: from n/a through 1.4.2.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xrxq-p636-j73q

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean up the allocated memory for the management command.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrxq-fc9m-fg9v

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxp-wj2g-wrxj

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrxm-mvqm-r553

Helm Path Traversal

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу