Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4346-23fm-8jv5

12 месяцев назад

A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4345-j8fj-2xr3

почти 4 года назад

Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).

EPSS: Низкий
github логотип

GHSA-4344-rjcf-rjfg

больше 3 лет назад

SQL injection vulnerability in Aimluck Aipo before 5.1.1, and Aipo for ASP before 5.1.1, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4344-frcp-j22q

больше 3 лет назад

Remote code execution due to insecure deserialization

EPSS: Средний
github логотип

GHSA-4344-38jh-mj6x

больше 3 лет назад

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4343-wxmv-4jg6

больше 3 лет назад

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.

EPSS: Низкий
github логотип

GHSA-4343-v7g7-q3hr

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

EPSS: Низкий
github логотип

GHSA-4343-c3c2-g6mv

почти 4 года назад

Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.

EPSS: Низкий
github логотип

GHSA-4343-6j55-fcq3

больше 3 лет назад

In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320644

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4343-3cxx-2jqg

больше 3 лет назад

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.

EPSS: Низкий
github логотип

GHSA-4343-27r5-p3v9

больше 3 лет назад

Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4342-x723-ch2f

5 месяцев назад

Next.js Improper Middleware Redirect Handling Leads to SSRF

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4342-v97q-65xg

почти 4 года назад

Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".

EPSS: Низкий
github логотип

GHSA-4342-mvf5-c32x

3 дня назад

Tanium addressed an information disclosure vulnerability in Threat Response.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-433x-mwqf-j53f

больше 3 лет назад

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.

EPSS: Средний
github логотип

GHSA-433x-hjc8-g7w7

почти 4 года назад

IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-433x-cqcq-wqv9

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in buffer mode. There is a race if indio_dev exits buffer mode in the middle of the interrupt that flushes the fifo. Fix this by calling synchronize_irq() to ensure that no interrupt is currently running when disabling buffer mode. Unable to handle kernel NULL pointer dereference at virtual address 00000000 when read [...] _find_first_bit_le from fxls8962af_fifo_flush+0x17c/0x290 fxls8962af_fifo_flush from fxls8962af_interrupt+0x80/0x178 fxls8962af_interrupt from irq_thread_fn+0x1c/0x7c irq_thread_fn from irq_thread+0x110/0x1f4 irq_thread from kthread+0xe0/0xfc kthread from ret_from_fork+0x14/0x2c

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-433w-mm6h-rv9p

больше 4 лет назад

Auth bypass in SAML provider

EPSS: Низкий
github логотип

GHSA-433w-8772-xfr8

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-433v-vgvp-w55j

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to perform unauthorized actions as administrators via a request that sets the wpcr_hidden_form_input parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4346-23fm-8jv5

A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-4345-j8fj-2xr3

Cross-site scripting (XSS) vulnerability in search.php in PHP Labware LabWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input box (query parameter).

1%
Низкий
почти 4 года назад
github логотип
GHSA-4344-rjcf-rjfg

SQL injection vulnerability in Aimluck Aipo before 5.1.1, and Aipo for ASP before 5.1.1, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4344-frcp-j22q

Remote code execution due to insecure deserialization

26%
Средний
больше 3 лет назад
github логотип
GHSA-4344-38jh-mj6x

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4343-wxmv-4jg6

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authenticated attacker to inject malicious script/tags via the name/description/comments parameter of various sections of the device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4343-v7g7-q3hr

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4343-c3c2-g6mv

Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.

8%
Низкий
почти 4 года назад
github логотип
GHSA-4343-6j55-fcq3

In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320644

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4343-3cxx-2jqg

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-4343-27r5-p3v9

Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.

CVSS3: 9.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-4342-x723-ch2f

Next.js Improper Middleware Redirect Handling Leads to SSRF

CVSS3: 6.5
5%
Низкий
5 месяцев назад
github логотип
GHSA-4342-v97q-65xg

Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".

1%
Низкий
почти 4 года назад
github логотип
GHSA-4342-mvf5-c32x

Tanium addressed an information disclosure vulnerability in Threat Response.

CVSS3: 4.9
0%
Низкий
3 дня назад
github логотип
GHSA-433x-mwqf-j53f

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to modify user information via a crafted URL, aka Bug ID CSCum77041.

46%
Средний
больше 3 лет назад
github логотип
GHSA-433x-hjc8-g7w7

IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-433x-cqcq-wqv9

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in buffer mode. There is a race if indio_dev exits buffer mode in the middle of the interrupt that flushes the fifo. Fix this by calling synchronize_irq() to ensure that no interrupt is currently running when disabling buffer mode. Unable to handle kernel NULL pointer dereference at virtual address 00000000 when read [...] _find_first_bit_le from fxls8962af_fifo_flush+0x17c/0x290 fxls8962af_fifo_flush from fxls8962af_interrupt+0x80/0x178 fxls8962af_interrupt from irq_thread_fn+0x1c/0x7c irq_thread_fn from irq_thread+0x110/0x1f4 irq_thread from kthread+0xe0/0xfc kthread from ret_from_fork+0x14/0x2c

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-433w-mm6h-rv9p

Auth bypass in SAML provider

больше 4 лет назад
github логотип
GHSA-433w-8772-xfr8

An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.

CVSS3: 7.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-433v-vgvp-w55j

Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to perform unauthorized actions as administrators via a request that sets the wpcr_hidden_form_input parameter.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу