Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42vh-q74p-v48f

около 4 лет назад

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

EPSS: Низкий
github логотип

GHSA-42vg-q6mw-cfh5

больше 3 лет назад

dotCMS allows remote authenticated users to execute arbitrary Java code

EPSS: Низкий
github логотип

GHSA-42vg-2q93-fj6j

больше 3 лет назад

LIEF vulnerable to heap based buffer overflow via print_binary function

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42vf-2jww-9pqr

больше 1 года назад

A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-42vc-wcrf-99q3

больше 3 лет назад

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

EPSS: Низкий
github логотип

GHSA-42vc-w69w-ghg7

около 1 года назад

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42vc-w257-pp26

почти 2 года назад

The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42vc-vfqh-cr2x

больше 1 года назад

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42vc-95ph-qmgq

больше 3 лет назад

Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42v9-rj5j-m2v5

больше 3 лет назад

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.

EPSS: Низкий
github логотип

GHSA-42v9-jcgw-cjx9

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42v8-53xx-p57h

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404.

EPSS: Низкий
github логотип

GHSA-42v8-4p4g-32vh

около 3 лет назад

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42v8-4h63-pf87

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42v5-vmqc-jx62

10 месяцев назад

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO &#8211; On-site SEO allows Privilege Escalation. This issue affects Rankology SEO &#8211; On-site SEO: from n/a through 2.2.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42v5-55fh-293w

больше 1 года назад

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42v5-23f7-54cx

около 3 лет назад

The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This would be highly complex to exploit as it would require the attacker to set the cookie a cookie for the targeted user.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-42v4-xpx8-cgxf

почти 4 года назад

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

EPSS: Низкий
github логотип

GHSA-42v4-cgq7-c8gf

больше 3 лет назад

A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42v4-3ghc-v5xh

больше 3 лет назад

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42vh-q74p-v48f

An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

0%
Низкий
около 4 лет назад
github логотип
GHSA-42vg-q6mw-cfh5

dotCMS allows remote authenticated users to execute arbitrary Java code

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42vg-2q93-fj6j

LIEF vulnerable to heap based buffer overflow via print_binary function

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42vf-2jww-9pqr

A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
3%
Низкий
больше 1 года назад
github логотип
GHSA-42vc-wcrf-99q3

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42vc-w69w-ghg7

The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-42vc-w257-pp26

The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-42vc-vfqh-cr2x

A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-42vc-95ph-qmgq

Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42v9-rj5j-m2v5

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42v9-jcgw-cjx9

Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule plugin <= 3.3.8 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42v8-53xx-p57h

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42v8-4p4g-32vh

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-42v8-4h63-pf87

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-42v5-vmqc-jx62

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO &#8211; On-site SEO allows Privilege Escalation. This issue affects Rankology SEO &#8211; On-site SEO: from n/a through 2.2.3.

CVSS3: 9.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-42v5-55fh-293w

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-42v5-23f7-54cx

The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This would be highly complex to exploit as it would require the attacker to set the cookie a cookie for the targeted user.

CVSS3: 4.7
3%
Низкий
около 3 лет назад
github логотип
GHSA-42v4-xpx8-cgxf

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

1%
Низкий
почти 4 года назад
github логотип
GHSA-42v4-cgq7-c8gf

A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42v4-3ghc-v5xh

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

23%
Средний
больше 3 лет назад

Уязвимостей на страницу