Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-xrmq-qg76-wcr7

9 дней назад

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION: 2.0.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xrmq-h6xp-2vgc

больше 3 лет назад

Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.

EPSS: Низкий
github логотип

GHSA-xrmp-99wj-p6jc

больше 6 лет назад

Prototype Pollution in deap

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrmm-q45r-f6gr

больше 3 лет назад

Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrmj-xm38-42wc

7 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xrmj-v7v7-vhq3

почти 4 года назад

Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."

EPSS: Низкий
github логотип

GHSA-xrmj-c7vj-9c4m

почти 4 года назад

The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrmh-cph2-4343

2 месяца назад

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.

EPSS: Низкий
github логотип

GHSA-xrmh-26m7-8f7p

больше 1 года назад

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrmg-5x28-jv6w

больше 3 лет назад

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrmf-4mwm-vr8j

около 2 лет назад

GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrmc-6wqq-99wc

больше 3 лет назад

The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

EPSS: Низкий
github логотип

GHSA-xrm7-9mcw-9wr5

11 месяцев назад

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrm7-6c5j-p27r

больше 3 лет назад

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.

EPSS: Низкий
github логотип

GHSA-xrm5-74w8-cr3j

больше 3 лет назад

The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.

EPSS: Низкий
github логотип

GHSA-xrm4-vc7m-v28j

10 месяцев назад

A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xrm4-23hc-gwj2

почти 2 года назад

The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the system.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xrm3-38hq-hp4q

8 месяцев назад

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrjx-pr69-2frv

почти 2 года назад

Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrjw-pqg4-p22x

4 месяца назад

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrmq-qg76-wcr7

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION: 2.0.

CVSS3: 3.7
0%
Низкий
9 дней назад
github логотип
GHSA-xrmq-h6xp-2vgc

Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrmp-99wj-p6jc

Prototype Pollution in deap

CVSS3: 7.3
больше 6 лет назад
github логотип
GHSA-xrmm-q45r-f6gr

Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrmj-xm38-42wc

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.

CVSS3: 2.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-xrmj-v7v7-vhq3

Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrmj-c7vj-9c4m

The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrmh-cph2-4343

Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating the login form. Attackers can inject specific SQL payloads like ' or '1'='1 to gain unauthorized administrative access to the system.

1%
Низкий
2 месяца назад
github логотип
GHSA-xrmh-26m7-8f7p

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrmg-5x28-jv6w

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrmf-4mwm-vr8j

GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrmc-6wqq-99wc

The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrm7-9mcw-9wr5

A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xrm7-6c5j-p27r

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xrm5-74w8-cr3j

The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sidebarMenu.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrm4-vc7m-v28j

A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xrm4-23hc-gwj2

The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the system.

CVSS3: 7.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrm3-38hq-hp4q

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xrjx-pr69-2frv

Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrjw-pqg4-p22x

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
4 месяца назад

Уязвимостей на страницу