Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-439p-jwxg-8ffc

больше 3 лет назад

PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-439m-pv8v-92q4

больше 1 года назад

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-439g-wrrf-f8f7

больше 1 года назад

A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected is an unknown function of the file /admin/search-medicalcard.php of the component Search. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-439g-ccc3-vp4h

около 1 года назад

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-439g-8mpp-5qvg

больше 3 лет назад

The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.

EPSS: Низкий
github логотип

GHSA-439g-6pcw-pgj7

больше 3 лет назад

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

EPSS: Низкий
github логотип

GHSA-439g-59mw-vpq8

6 месяцев назад

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08), and was fixed in commit 95322c5121dbd7070f3bd54f2848079654a0a8ea (dated 2025-03-31). The attack can be launched remotely. CWE Definition of the Vulnerability: CWE-79.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-439f-hv4q-rmc5

почти 4 года назад

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.

EPSS: Низкий
github логотип

GHSA-439f-fqrh-gmv2

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from v1.4 before v1.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-439f-cgjv-3g68

9 месяцев назад

Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be executed on the web browser of the moderator user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-439f-2pm4-424q

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: pinctrl: renesas: rzn1: Fix possible null-ptr-deref in sh_pfc_map_resources() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-439c-m266-7555

почти 4 года назад

Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.

EPSS: Низкий
github логотип

GHSA-4399-hpjw-w4jp

больше 3 лет назад

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

EPSS: Низкий
github логотип

GHSA-4399-46r4-5rmv

больше 3 лет назад

GeniXCMS Cross-site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4398-q7v4-m5w6

около 2 лет назад

An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4398-mf32-hq2w

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the decryptFile method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10502.

EPSS: Средний
github логотип

GHSA-4397-q3r3-9665

больше 1 года назад

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4397-jww6-prqq

больше 3 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4397-h7gg-cgr7

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to admin_addadmin.html.

EPSS: Низкий
github логотип

GHSA-4396-rhqw-4hpg

больше 3 лет назад

Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-439p-jwxg-8ffc

PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-439m-pv8v-92q4

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-439g-wrrf-f8f7

A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected is an unknown function of the file /admin/search-medicalcard.php of the component Search. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-439g-ccc3-vp4h

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-439g-8mpp-5qvg

The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-439g-6pcw-pgj7

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-439g-59mw-vpq8

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08), and was fixed in commit 95322c5121dbd7070f3bd54f2848079654a0a8ea (dated 2025-03-31). The attack can be launched remotely. CWE Definition of the Vulnerability: CWE-79.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-439f-hv4q-rmc5

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.

2%
Низкий
почти 4 года назад
github логотип
GHSA-439f-fqrh-gmv2

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from v1.4 before v1.5.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-439f-cgjv-3g68

Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be executed on the web browser of the moderator user.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-439f-2pm4-424q

In the Linux kernel, the following vulnerability has been resolved: pinctrl: renesas: rzn1: Fix possible null-ptr-deref in sh_pfc_map_resources() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using 'res' after devm_ioremap_resource() that will check it to avoid null-ptr-deref. And use devm_platform_get_and_ioremap_resource() to simplify code.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-439c-m266-7555

Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-4399-hpjw-w4jp

SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4399-46r4-5rmv

GeniXCMS Cross-site Scripting (XSS)

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4398-q7v4-m5w6

An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-4398-mf32-hq2w

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the decryptFile method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10502.

13%
Средний
больше 3 лет назад
github логотип
GHSA-4397-q3r3-9665

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4397-jww6-prqq

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-4397-h7gg-cgr7

Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to admin_addadmin.html.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4396-rhqw-4hpg

Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

4%
Низкий
больше 3 лет назад

Уязвимостей на страницу