Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-4395-qwxq-qcc7

больше 1 года назад

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4395-98rh-2625

почти 4 года назад

The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.

EPSS: Низкий
github логотип

GHSA-4395-7xhp-289j

больше 3 лет назад

ok-file-formats through 2021-04-29 has a heap-based buffer overflow in the ok_csv_circular_buffer_read function in ok_csv.c.

EPSS: Низкий
github логотип

GHSA-4394-5727-8668

больше 3 лет назад

Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.

EPSS: Низкий
github логотип

GHSA-4393-ch2m-6pmx

почти 4 года назад

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4392-jjcv-v827

около 4 лет назад

An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.

EPSS: Низкий
github логотип

GHSA-4392-4w2j-v4vh

больше 1 года назад

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-438x-xp6g-ppjf

5 месяцев назад

Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress – ConveyThis allows Object Injection. This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 264.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-438x-c47w-35hc

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Leishman Mail Subscribe List allows Stored XSS. This issue affects Mail Subscribe List: from n/a through 2.1.10.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-438x-9g8x-78p5

больше 2 лет назад

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-438x-56gx-w64g

почти 4 года назад

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

EPSS: Низкий
github логотип

GHSA-438x-3xx9-xwjp

8 месяцев назад

Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.

EPSS: Низкий
github логотип

GHSA-438x-2p9v-g8h9

больше 3 лет назад

Camaleon CMS Insufficient Session Expiration vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-438w-xvxp-m9c6

почти 4 года назад

The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."

EPSS: Высокий
github логотип

GHSA-438w-rjj9-5fjf

больше 3 лет назад

Cross-site Scripting in Jenkins Repository Connector Plugin

CVSS3: 8
EPSS: Средний
github логотип

GHSA-438w-mprg-3r4x

около 2 месяцев назад

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-438r-9269-8f2c

больше 3 лет назад

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-438q-mx46-fpm4

почти 2 года назад

In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-438p-qhhr-8gxm

больше 3 лет назад

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

EPSS: Низкий
github логотип

GHSA-438p-f52x-jj25

около 3 лет назад

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4395-qwxq-qcc7

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the file student_form.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269276.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4395-98rh-2625

The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4395-7xhp-289j

ok-file-formats through 2021-04-29 has a heap-based buffer overflow in the ok_csv_circular_buffer_read function in ok_csv.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4394-5727-8668

Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-4393-ch2m-6pmx

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-4392-jjcv-v827

An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.

0%
Низкий
около 4 лет назад
github логотип
GHSA-4392-4w2j-v4vh

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-438x-xp6g-ppjf

Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress – ConveyThis allows Object Injection. This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 264.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-438x-c47w-35hc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Leishman Mail Subscribe List allows Stored XSS. This issue affects Mail Subscribe List: from n/a through 2.1.10.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-438x-9g8x-78p5

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

CVSS3: 9.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-438x-56gx-w64g

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

4%
Низкий
почти 4 года назад
github логотип
GHSA-438x-3xx9-xwjp

Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.

0%
Низкий
8 месяцев назад
github логотип
GHSA-438x-2p9v-g8h9

Camaleon CMS Insufficient Session Expiration vulnerability

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-438w-xvxp-m9c6

The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."

89%
Высокий
почти 4 года назад
github логотип
GHSA-438w-rjj9-5fjf

Cross-site Scripting in Jenkins Repository Connector Plugin

CVSS3: 8
32%
Средний
больше 3 лет назад
github логотип
GHSA-438w-mprg-3r4x

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'uacf7_get_generated_pdf' function in all versions up to, and including, 3.5.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to generate and get form submission PDF, when the "PDF Generator" and the "Database" addons are enabled (disabled by default).

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-438r-9269-8f2c

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-438q-mx46-fpm4

In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-438p-qhhr-8gxm

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-438p-f52x-jj25

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 before 2022.1.110.1.02. One parameter allows SQL injection.

CVSS3: 8.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу