Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-44w5-q257-8428

больше 3 лет назад

Exposure of password hashes in notrinos/notrinos-erp

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44w4-f424-89xh

около 1 года назад

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-44w3-wrmw-j9hx

больше 3 лет назад

IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-44w3-qvp9-4hh4

больше 3 лет назад

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44w3-4x9p-xmff

около 1 года назад

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44w2-xrgw-gqvj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

EPSS: Низкий
github логотип

GHSA-44w2-crmp-vc4v

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44w2-cgm4-695p

6 месяцев назад

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.

EPSS: Низкий
github логотип

GHSA-44w2-c6gq-2xxx

около 1 года назад

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44vx-q8jj-wcwm

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.

EPSS: Низкий
github логотип

GHSA-44vx-c3xh-577j

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-44vw-x4jf-3q2f

около 2 лет назад

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-44vw-5m8p-p6fc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

EPSS: Низкий
github логотип

GHSA-44vv-qwrx-c34r

3 месяца назад

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44vv-mm86-7cg6

больше 3 лет назад

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-44vv-j7c4-9vf4

около 2 лет назад

Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-44vv-6vcv-9h7r

около 1 года назад

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44vv-4w2p-9wqf

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44vv-2mpg-8hv5

почти 2 года назад

Microsoft Office OneNote Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44vr-rwwj-p88h

больше 3 лет назад

Shescape vulnerable to insufficient escaping of whitespace

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44w5-q257-8428

Exposure of password hashes in notrinos/notrinos-erp

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44w4-f424-89xh

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-44w3-wrmw-j9hx

IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.

CVSS3: 8.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44w3-qvp9-4hh4

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44w3-4x9p-xmff

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-44w2-xrgw-gqvj

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44w2-crmp-vc4v

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-44w2-cgm4-695p

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined.

1%
Низкий
6 месяцев назад
github логотип
GHSA-44w2-c6gq-2xxx

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-44vx-q8jj-wcwm

Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vx-c3xh-577j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-44vw-x4jf-3q2f

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-44vw-5m8p-p6fc

Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

1%
Низкий
почти 4 года назад
github логотип
GHSA-44vv-qwrx-c34r

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-44vv-mm86-7cg6

phpMyAdmin server-side request forgery (SSRF)

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vv-j7c4-9vf4

Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-44vv-6vcv-9h7r

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
6%
Низкий
около 1 года назад
github логотип
GHSA-44vv-4w2p-9wqf

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vv-2mpg-8hv5

Microsoft Office OneNote Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-44vr-rwwj-p88h

Shescape vulnerable to insufficient escaping of whitespace

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу