Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-xrx4-x2w9-xf6v

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrx4-vq84-23w6

больше 3 лет назад

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xrx4-hm38-w6hm

почти 4 года назад

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

EPSS: Низкий
github логотип

GHSA-xrx4-hghv-p3q8

почти 4 года назад

Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-xrx4-g976-77rm

больше 2 лет назад

.NET Framework Spoofing Vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xrx4-5pqh-8mr5

больше 3 лет назад

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrx4-52w3-mpjx

больше 3 лет назад

The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.

EPSS: Низкий
github логотип

GHSA-xrx3-f4cm-9v4f

около 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrx3-4r6h-5xp6

почти 4 года назад

Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

EPSS: Низкий
github логотип

GHSA-xrx2-hcfr-w76f

больше 3 лет назад

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrwx-phm3-vhq4

больше 3 лет назад

In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384

EPSS: Низкий
github логотип

GHSA-xrww-68c4-qq72

около 3 лет назад

Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xrww-67cv-gqrx

около 3 лет назад

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall srcmac (WORD|null) srcip (A.B.C.D|null) dstip (A.B.C.D|null) protocol (none|tcp|udp|icmp) srcport (<1-65535>|null) dstport (<1-65535>|null) policy (drop|accept) description (WORD|null)' command template.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrww-3rp8-cfmx

больше 3 лет назад

A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrwv-x9mf-8rh3

больше 1 года назад

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xrwv-jchf-q5j2

больше 3 лет назад

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.

EPSS: Низкий
github логотип

GHSA-xrwv-8jhj-x69w

12 месяцев назад

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrwv-6rch-f7vv

больше 3 лет назад

Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrwr-pg2p-3r5m

больше 3 лет назад

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xrwr-fgmg-h9xp

больше 1 года назад

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrx4-x2w9-xf6v

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrx4-vq84-23w6

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CVSS3: 9.8
41%
Средний
больше 3 лет назад
github логотип
GHSA-xrx4-hm38-w6hm

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrx4-hghv-p3q8

Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrx4-g976-77rm

.NET Framework Spoofing Vulnerability

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrx4-5pqh-8mr5

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrx4-52w3-mpjx

The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrx3-f4cm-9v4f

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrx3-4r6h-5xp6

Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xrx2-hcfr-w76f

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrwx-phm3-vhq4

In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrww-68c4-qq72

Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.

CVSS3: 7.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrww-67cv-gqrx

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall srcmac (WORD|null) srcip (A.B.C.D|null) dstip (A.B.C.D|null) protocol (none|tcp|udp|icmp) srcport (<1-65535>|null) dstport (<1-65535>|null) policy (drop|accept) description (WORD|null)' command template.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrww-3rp8-cfmx

A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrwv-x9mf-8rh3

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

CVSS3: 8.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xrwv-jchf-q5j2

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrwv-8jhj-x69w

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xrwv-6rch-f7vv

Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

CVSS3: 5.4
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrwr-pg2p-3r5m

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrwr-fgmg-h9xp

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVSS3: 7.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу