Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-4453-jqxv-ffj9

больше 3 лет назад

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4453-g295-24mh

больше 3 лет назад

Cross site scripting in Elefant CMS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4453-3pwj-4w2x

почти 4 года назад

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

EPSS: Низкий
github логотип

GHSA-4452-v8jv-h496

почти 2 года назад

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4452-rwq3-2x44

11 месяцев назад

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4452-2568-9wpm

почти 4 года назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-444x-5q6g-3jr8

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-444w-xm89-r2p5

почти 4 года назад

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-444v-6hj2-v93m

больше 1 года назад

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-444r-jhgm-mr5f

больше 3 лет назад

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Средний
github логотип

GHSA-444r-2xr3-rxhv

больше 3 лет назад

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

EPSS: Низкий
github логотип

GHSA-444q-fgvg-7w24

2 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-444q-7pcf-frfw

почти 4 года назад

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

EPSS: Низкий
github логотип

GHSA-444p-vrjm-ch4f

6 месяцев назад

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-444p-87wx-v9fp

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston allows PHP Local File Inclusion. This issue affects Ziston: from n/a through n/a.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-444m-px7r-qpvv

15 дней назад

weixin4j has Improperly Controlled Sequential Memory Allocation

EPSS: Низкий
github логотип

GHSA-444j-cwp6-3fgg

больше 3 лет назад

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-444j-ccxr-jrr5

около 2 лет назад

The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body and footer content parameters in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-444h-qfvw-6mmm

почти 4 года назад

Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

EPSS: Низкий
github логотип

GHSA-444h-fpxc-vh3q

почти 4 года назад

Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4453-jqxv-ffj9

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-4453-g295-24mh

Cross site scripting in Elefant CMS

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4453-3pwj-4w2x

network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-4452-v8jv-h496

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-4452-rwq3-2x44

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.

CVSS3: 7.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-4452-2568-9wpm

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-444x-5q6g-3jr8

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia - idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.6.93.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-444w-xm89-r2p5

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-444v-6hj2-v93m

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-444r-jhgm-mr5f

Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.

29%
Средний
больше 3 лет назад
github логотип
GHSA-444r-2xr3-rxhv

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-444q-fgvg-7w24

Rejected reason: Not used

2 месяца назад
github логотип
GHSA-444q-7pcf-frfw

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

3%
Низкий
почти 4 года назад
github логотип
GHSA-444p-vrjm-ch4f

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-444p-87wx-v9fp

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston allows PHP Local File Inclusion. This issue affects Ziston: from n/a through n/a.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-444m-px7r-qpvv

weixin4j has Improperly Controlled Sequential Memory Allocation

0%
Низкий
15 дней назад
github логотип
GHSA-444j-cwp6-3fgg

Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-444j-ccxr-jrr5

The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body and footer content parameters in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin.

CVSS3: 4.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-444h-qfvw-6mmm

Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

1%
Низкий
почти 4 года назад
github логотип
GHSA-444h-fpxc-vh3q

Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу