Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-43r8-6qx5-w655

больше 3 лет назад

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

EPSS: Низкий
github логотип

GHSA-43r8-23m5-329f

больше 1 года назад

Microsoft Outlook Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-43r7-fmc5-8629

больше 3 лет назад

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

EPSS: Низкий
github логотип

GHSA-43r6-r8w4-qp6c

почти 4 года назад

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

EPSS: Низкий
github логотип

GHSA-43r5-v8pm-grg9

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-43r5-42q2-7483

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43r4-vm25-qm78

больше 3 лет назад

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

EPSS: Низкий
github логотип

GHSA-43r4-72q9-7mv7

больше 3 лет назад

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43r3-p9qg-f74p

больше 3 лет назад

Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.

EPSS: Средний
github логотип

GHSA-43r3-f7j4-6552

больше 3 лет назад

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

EPSS: Низкий
github логотип

GHSA-43r2-vc56-g759

больше 3 лет назад

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

EPSS: Низкий
github логотип

GHSA-43r2-rv47-2g9m

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPyog WPYog Documents allows Reflected XSS. This issue affects WPYog Documents: from n/a through 1.3.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43r2-j3m4-vcpc

больше 3 лет назад

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

EPSS: Низкий
github логотип

GHSA-43qx-6r5f-7vgw

больше 2 лет назад

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-43qx-5g4q-qv73

больше 3 лет назад

The mintToken function of a smart contract implementation for ETHERCASH (ETC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43qw-p4wg-qvxr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

EPSS: Низкий
github логотип

GHSA-43qv-gqwc-rjxf

больше 3 лет назад

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

EPSS: Низкий
github логотип

GHSA-43qr-pjmr-cgfv

9 месяцев назад

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43qr-ph4f-wq48

почти 4 года назад

Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43qr-7pjx-rp3v

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FameThemes OnePress allows Stored XSS.This issue affects OnePress: from n/a through 2.3.8.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43r8-6qx5-w655

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-43r8-23m5-329f

Microsoft Outlook Remote Code Execution Vulnerability

CVSS3: 8.8
15%
Средний
больше 1 года назад
github логотип
GHSA-43r7-fmc5-8629

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r6-r8w4-qp6c

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

8%
Низкий
почти 4 года назад
github логотип
GHSA-43r5-v8pm-grg9

Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r5-42q2-7483

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r4-vm25-qm78

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r4-72q9-7mv7

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r3-p9qg-f74p

Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.

19%
Средний
больше 3 лет назад
github логотип
GHSA-43r3-f7j4-6552

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-43r2-vc56-g759

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43r2-rv47-2g9m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPyog WPYog Documents allows Reflected XSS. This issue affects WPYog Documents: from n/a through 1.3.3.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-43r2-j3m4-vcpc

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-43qx-6r5f-7vgw

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43qx-5g4q-qv73

The mintToken function of a smart contract implementation for ETHERCASH (ETC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qw-p4wg-qvxr

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qv-gqwc-rjxf

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qr-pjmr-cgfv

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-43qr-ph4f-wq48

Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-43qr-7pjx-rp3v

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FameThemes OnePress allows Stored XSS.This issue affects OnePress: from n/a through 2.3.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу