Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 308

Количество 288 308

github логотип

GHSA-xxm6-ff3x-v4vm

больше 2 лет назад

thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxm6-c9w6-3g54

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

EPSS: Низкий
github логотип

GHSA-xxm5-p2jg-xh9g

больше 3 лет назад

SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

EPSS: Низкий
github логотип

GHSA-xxm5-g29j-f9vq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

EPSS: Низкий
github логотип

GHSA-xxm4-g3v8-g83q

почти 2 года назад

In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xxm4-8498-pwrr

больше 3 лет назад

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

EPSS: Низкий
github логотип

GHSA-xxm4-3cqf-2pcc

больше 3 лет назад

PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

EPSS: Низкий
github логотип

GHSA-xxm3-fp55-pm48

около 3 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xxjw-vw5q-j33v

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjw-q2gq-6w22

около 3 лет назад

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxjw-mqrg-2r3c

6 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xxjw-jpj3-73mg

около 3 лет назад

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-jphq-5x96

больше 3 лет назад

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

EPSS: Низкий
github логотип

GHSA-xxjw-fx2f-9c38

5 месяцев назад

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-6qx2-crcm

около 3 лет назад

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjv-vh49-qq33

около 1 года назад

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjv-pwp6-p43h

около 3 лет назад

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

EPSS: Низкий
github логотип

GHSA-xxjv-9p3v-x2hv

7 месяцев назад

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjr-c99v-4h9c

около 2 лет назад

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxjm-jvw6-6mm7

больше 2 лет назад

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxm6-ff3x-v4vm

thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxm6-c9w6-3g54

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

8%
Низкий
около 3 лет назад
github логотип
GHSA-xxm5-p2jg-xh9g

SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxm5-g29j-f9vq

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxm4-g3v8-g83q

In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxm4-8498-pwrr

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxm4-3cqf-2pcc

PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-xxm3-fp55-pm48

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-xxjw-vw5q-j33v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xxjw-q2gq-6w22

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxjw-mqrg-2r3c

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-xxjw-jpj3-73mg

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxjw-jphq-5x96

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxjw-fx2f-9c38

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxjw-6qx2-crcm

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxjv-vh49-qq33

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xxjv-pwp6-p43h

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxjv-9p3v-x2hv

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xxjr-c99v-4h9c

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxjm-jvw6-6mm7

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу