Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-44cm-p9q7-rr3p

больше 3 лет назад

Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44cj-54hp-jr6f

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

EPSS: Средний
github логотип

GHSA-44ch-2f85-f4rm

почти 4 года назад

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.

EPSS: Низкий
github логотип

GHSA-44cg-qcpr-fwjh

почти 4 года назад

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-44cg-m8vj-gr6h

больше 3 лет назад

Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information.

EPSS: Высокий
github логотип

GHSA-44cg-7j74-fvp3

больше 3 лет назад

Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

EPSS: Низкий
github логотип

GHSA-44cf-cppv-qcvq

около 1 года назад

A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44cc-c4hq-r7vv

больше 3 лет назад

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

EPSS: Низкий
github логотип

GHSA-44cc-43rp-5947

около 2 лет назад

JupyterLab vulnerable to potential authentication and CSRF tokens leak

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-44c9-7g74-x3pf

больше 3 лет назад

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44c7-rp6q-gcrh

больше 3 лет назад

In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.

EPSS: Низкий
github логотип

GHSA-44c7-hc99-224f

больше 3 лет назад

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44c7-h9h2-wj6v

больше 3 лет назад

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44c7-chxm-hq3q

около 1 года назад

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-44c7-92p2-r6w4

больше 2 лет назад

The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-44c7-8q42-vpfv

больше 3 лет назад

core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-44c7-43g3-f86m

8 месяцев назад

An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-44c7-327r-j4x7

больше 3 лет назад

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-44c7-2233-xwr4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."

EPSS: Средний
github логотип

GHSA-44c6-4v22-4mhx

больше 4 лет назад

semver-regex Regular Expression Denial of Service (ReDOS)

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44cm-p9q7-rr3p

Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44cj-54hp-jr6f

Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

13%
Средний
почти 4 года назад
github логотип
GHSA-44ch-2f85-f4rm

Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.

4%
Низкий
почти 4 года назад
github логотип
GHSA-44cg-qcpr-fwjh

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-44cg-m8vj-gr6h

Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information.

81%
Высокий
больше 3 лет назад
github логотип
GHSA-44cg-7j74-fvp3

Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44cf-cppv-qcvq

A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-44cc-c4hq-r7vv

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-44cc-43rp-5947

JupyterLab vulnerable to potential authentication and CSRF tokens leak

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-44c9-7g74-x3pf

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44c7-rp6q-gcrh

In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-44c7-hc99-224f

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a client. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-44c7-h9h2-wj6v

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44c7-chxm-hq3q

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

CVSS3: 9.8
14%
Средний
около 1 года назад
github логотип
GHSA-44c7-92p2-r6w4

The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-44c7-8q42-vpfv

core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

CVSS3: 9.8
51%
Средний
больше 3 лет назад
github логотип
GHSA-44c7-43g3-f86m

An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.

CVSS3: 7.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-44c7-327r-j4x7

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

CVSS3: 6.5
15%
Средний
больше 3 лет назад
github логотип
GHSA-44c7-2233-xwr4

Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."

41%
Средний
больше 3 лет назад
github логотип
GHSA-44c6-4v22-4mhx

semver-regex Regular Expression Denial of Service (ReDOS)

CVSS3: 7.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу