Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-426g-4c29-jjpr

8 месяцев назад

A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-426f-2r7q-j2xm

10 месяцев назад

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4269-qr56-7rgx

больше 3 лет назад

Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4269-mcfh-cp7q

5 месяцев назад

Indico may disclose unauthorized user details access via legacy API

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4269-gch5-8w3c

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

EPSS: Низкий
github логотип

GHSA-4269-36rj-fxq8

больше 2 лет назад

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4268-mm99-gpjc

2 месяца назад

A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4268-53h5-jjpj

больше 3 лет назад

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4267-v6qh-xchc

больше 3 лет назад

** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check.

EPSS: Низкий
github логотип

GHSA-4265-qr4f-qwmv

больше 3 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.

EPSS: Средний
github логотип

GHSA-4265-pfr7-6xjv

3 месяца назад

A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.

EPSS: Низкий
github логотип

GHSA-4265-mmrf-q5w3

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: possible module reference underflow in error path dst->ops is set on when nft_expr_clone() fails, but module refcount has not been bumped yet, therefore nft_expr_destroy() leads to module reference underflow.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4265-mh49-263h

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4265-ccf5-phj5

почти 2 года назад

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4263-q746-94mw

больше 3 лет назад

Uncontrolled Resource Consumption in fast-string-search

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4263-fvh8-fmg2

больше 3 лет назад

An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4262-wr7p-gpcj

больше 3 лет назад

Rundeck Community Edition vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4262-ffcv-r365

больше 3 лет назад

VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4262-7rxm-xfp7

почти 2 года назад

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4262-475v-w946

больше 3 лет назад

Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the (1) boxname parameter to theme/superchrome/box.php and the (2) theme parameter to phpclanwebsite/footer.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-426g-4c29-jjpr

A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-426f-2r7q-j2xm

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4269-qr56-7rgx

Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4269-mcfh-cp7q

Indico may disclose unauthorized user details access via legacy API

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4269-gch5-8w3c

Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4269-36rj-fxq8

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4268-mm99-gpjc

A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4268-53h5-jjpj

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4267-v6qh-xchc

** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4265-qr4f-qwmv

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.

30%
Средний
больше 3 лет назад
github логотип
GHSA-4265-pfr7-6xjv

A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.

0%
Низкий
3 месяца назад
github логотип
GHSA-4265-mmrf-q5w3

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: possible module reference underflow in error path dst->ops is set on when nft_expr_clone() fails, but module refcount has not been bumped yet, therefore nft_expr_destroy() leads to module reference underflow.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4265-mh49-263h

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4265-ccf5-phj5

Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4263-q746-94mw

Uncontrolled Resource Consumption in fast-string-search

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4263-fvh8-fmg2

An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4262-wr7p-gpcj

Rundeck Community Edition vulnerable to Cross-site Scripting

CVSS3: 6.1
9%
Низкий
больше 3 лет назад
github логотип
GHSA-4262-ffcv-r365

VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4262-7rxm-xfp7

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

CVSS3: 9.8
13%
Средний
почти 2 года назад
github логотип
GHSA-4262-475v-w946

Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the (1) boxname parameter to theme/superchrome/box.php and the (2) theme parameter to phpclanwebsite/footer.php.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу