Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-xrjf-phvv-r4vr

почти 4 года назад

Command injection in strapi

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrjf-j24x-4gqj

почти 3 года назад

A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrj9-vwwj-2w2c

почти 4 года назад

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

EPSS: Средний
github логотип

GHSA-xrj9-mw57-j34v

3 месяца назад

AstrBot contains a directory traversal vulnerability

EPSS: Низкий
github логотип

GHSA-xrj9-h79q-8446

почти 4 года назад

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

EPSS: Низкий
github логотип

GHSA-xrj9-8xhq-9gjh

почти 4 года назад

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xrj9-7qw9-gvw5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

EPSS: Низкий
github логотип

GHSA-xrj7-x7gp-wwqr

около 2 лет назад

Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrj7-5h89-vjmj

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

EPSS: Низкий
github логотип

GHSA-xrj7-4gfh-q9h7

около 4 лет назад

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrj6-cww5-qm75

больше 3 лет назад

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrj6-96j3-q3jj

почти 4 года назад

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrj6-9329-h97g

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.

EPSS: Низкий
github логотип

GHSA-xrj4-x4gq-r76x

почти 4 года назад

Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

EPSS: Низкий
github логотип

GHSA-xrj4-gqr5-5gq8

больше 2 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xrj4-fxgw-43xg

больше 3 лет назад

An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xrj4-4g3m-87pf

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions where a rose_neigh structure is freed while still being referenced by other code paths. For example, when rose_neigh->use becomes zero during an ioctl operation via rose_rt_ioctl(), the structure may be removed while its timer is still active, potentially causing use-after-free issues. This patch changes the type of 'use' from unsigned short to refcount_t and updates all code paths to use rose_neigh_hold() and rose_neigh_put() which operate reference counts atomically.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xrj3-j65c-j9gg

больше 3 лет назад

Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40, WNR618 before 1.1.0.40, and D7000 before 1.0.1.50.

EPSS: Низкий
github логотип

GHSA-xrj2-8v34-f8cx

почти 4 года назад

Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrhx-47w7-f9pm

почти 4 года назад

An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrjf-phvv-r4vr

Command injection in strapi

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrjf-j24x-4gqj

A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 04b223813f0e336aab50bff140d0f5889c31dbec. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221503.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrj9-vwwj-2w2c

PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

66%
Средний
почти 4 года назад
github логотип
GHSA-xrj9-mw57-j34v

AstrBot contains a directory traversal vulnerability

1%
Низкий
3 месяца назад
github логотип
GHSA-xrj9-h79q-8446

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrj9-8xhq-9gjh

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

CVSS3: 9.8
33%
Средний
почти 4 года назад
github логотип
GHSA-xrj9-7qw9-gvw5

Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj7-x7gp-wwqr

Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrj7-5h89-vjmj

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj7-4gfh-q9h7

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

CVSS3: 6.1
3%
Низкий
около 4 лет назад
github логотип
GHSA-xrj6-cww5-qm75

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj6-96j3-q3jj

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrj6-9329-h97g

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrj4-x4gq-r76x

Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

6%
Низкий
почти 4 года назад
github логотип
GHSA-xrj4-gqr5-5gq8

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

CVSS3: 8.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrj4-fxgw-43xg

An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.

CVSS3: 5.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj4-4g3m-87pf

In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions where a rose_neigh structure is freed while still being referenced by other code paths. For example, when rose_neigh->use becomes zero during an ioctl operation via rose_rt_ioctl(), the structure may be removed while its timer is still active, potentially causing use-after-free issues. This patch changes the type of 'use' from unsigned short to refcount_t and updates all code paths to use rose_neigh_hold() and rose_neigh_put() which operate reference counts atomically.

CVSS3: 7
0%
Низкий
5 месяцев назад
github логотип
GHSA-xrj3-j65c-j9gg

Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40, WNR618 before 1.1.0.40, and D7000 before 1.0.1.50.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrj2-8v34-f8cx

Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrhx-47w7-f9pm

An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу