Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xrwq-4gxw-wvh5

почти 4 года назад

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrwp-4qvv-59wr

около 4 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrwm-6gg9-475c

почти 4 года назад

xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.

EPSS: Низкий
github логотип

GHSA-xrwm-3443-592w

почти 4 года назад

Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

EPSS: Низкий
github логотип

GHSA-xrwj-6h7r-w997

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.3 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrwg-mqj6-6m22

3 месяца назад

Envoy Extension Policy lua scripts injection causes arbitrary command execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrwf-c2jf-x7v8

около 1 года назад

Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through 1.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrwf-8f3p-hr54

почти 4 года назад

Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrwc-fmfq-559j

почти 4 года назад

An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1437, CVE-2019-1438.

EPSS: Низкий
github логотип

GHSA-xrw9-rhv5-78jv

почти 4 года назад

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

EPSS: Средний
github логотип

GHSA-xrw9-r35x-x878

5 месяцев назад

Zitadel allows brute-forcing authentication factors

EPSS: Низкий
github логотип

GHSA-xrw8-8992-37w4

больше 2 лет назад

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xrw8-7vj3-m4f7

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compete Themes Unlimited allows Stored XSS. This issue affects Unlimited: from n/a through 1.45.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrw7-w8px-rf87

почти 4 года назад

Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition Venue Management. While the vulnerability is in Oracle Hospitality Simphony First Edition Venue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony First Edition Venue Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony First Edition Venue Management accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xrw7-9m6r-77jp

почти 4 года назад

Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrw7-56rh-2jrq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: musb: sunxi: Fix accessing an released usb phy Commit 6ed05c68cbca ("usb: musb: sunxi: Explicitly release USB PHY on exit") will cause that usb phy @glue->xceiv is accessed after released. 1) register platform driver @sunxi_musb_driver // get the usb phy @glue->xceiv sunxi_musb_probe() -> devm_usb_get_phy(). 2) register and unregister platform driver @musb_driver musb_probe() -> sunxi_musb_init() use the phy here //the phy is released here musb_remove() -> sunxi_musb_exit() -> devm_usb_put_phy() 3) register @musb_driver again musb_probe() -> sunxi_musb_init() use the phy here but the phy has been released at 2). ... Fixed by reverting the commit, namely, removing devm_usb_put_phy() from sunxi_musb_exit().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrw7-4wgq-5hg3

почти 4 года назад

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

EPSS: Низкий
github логотип

GHSA-xrw6-rg6p-44v6

больше 1 года назад

SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrw6-gq4w-mj7r

почти 4 года назад

Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs (dwmapi.dll, PROPSYS.dll, cscapi.dll, SAMLIB.dll, netbios.dll, winhttp.dll, security.dll, ntmarta.dll, WindowsCodecs.dll, apphelp.dll) loaded by the SwisscomTVMediaHelper.exe process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrw3-wqph-3fxg

около 3 лет назад

Withdrawn: wallabag subject to Improper Authorization via annotations

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrwq-4gxw-wvh5

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrwp-4qvv-59wr

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrwm-6gg9-475c

xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrwm-3443-592w

Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrwj-6h7r-w997

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.3 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrwg-mqj6-6m22

Envoy Extension Policy lua scripts injection causes arbitrary command execution

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xrwf-c2jf-x7v8

Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through 1.0.2.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xrwf-8f3p-hr54

Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrwc-fmfq-559j

An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1437, CVE-2019-1438.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrw9-rhv5-78jv

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

21%
Средний
почти 4 года назад
github логотип
GHSA-xrw9-r35x-x878

Zitadel allows brute-forcing authentication factors

0%
Низкий
5 месяцев назад
github логотип
GHSA-xrw8-8992-37w4

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
39%
Средний
больше 2 лет назад
github логотип
GHSA-xrw8-7vj3-m4f7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compete Themes Unlimited allows Stored XSS. This issue affects Unlimited: from n/a through 1.45.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xrw7-w8px-rf87

Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony First Edition Venue Management. While the vulnerability is in Oracle Hospitality Simphony First Edition Venue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Simphony First Edition Venue Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Simphony First Edition Venue Management accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).

CVSS3: 6.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrw7-9m6r-77jp

Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrw7-56rh-2jrq

In the Linux kernel, the following vulnerability has been resolved: usb: musb: sunxi: Fix accessing an released usb phy Commit 6ed05c68cbca ("usb: musb: sunxi: Explicitly release USB PHY on exit") will cause that usb phy @glue->xceiv is accessed after released. 1) register platform driver @sunxi_musb_driver // get the usb phy @glue->xceiv sunxi_musb_probe() -> devm_usb_get_phy(). 2) register and unregister platform driver @musb_driver musb_probe() -> sunxi_musb_init() use the phy here //the phy is released here musb_remove() -> sunxi_musb_exit() -> devm_usb_put_phy() 3) register @musb_driver again musb_probe() -> sunxi_musb_init() use the phy here but the phy has been released at 2). ... Fixed by reverting the commit, namely, removing devm_usb_put_phy() from sunxi_musb_exit().

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrw7-4wgq-5hg3

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrw6-rg6p-44v6

SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrw6-gq4w-mj7r

Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs (dwmapi.dll, PROPSYS.dll, cscapi.dll, SAMLIB.dll, netbios.dll, winhttp.dll, security.dll, ntmarta.dll, WindowsCodecs.dll, apphelp.dll) loaded by the SwisscomTVMediaHelper.exe process.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrw3-wqph-3fxg

Withdrawn: wallabag subject to Improper Authorization via annotations

CVSS3: 4.3
около 3 лет назад

Уязвимостей на страницу