Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-423j-38qf-whqh

почти 3 года назад

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225347.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-423h-q743-cc99

почти 2 года назад

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250562 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-423h-mr5w-x796

почти 2 года назад

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-423h-j3gq-xjw2

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-423h-352x-q557

больше 3 лет назад

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-423g-qv8g-mgcc

больше 3 лет назад

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of quota, or create an unbounded number of nodes owned by dom0, thus running xenstored out of memory A malicious guest administrator can cause a denial of service against a specific guest or against the whole host. All systems using oxenstored are vulnerable. Building and using oxenstored is the default in the upstream Xen distribution, if the Ocaml compiler is available. Systems using C xenstored are not vulnerable.

EPSS: Низкий
github логотип

GHSA-423g-mrq6-vpvp

больше 1 года назад

In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-423c-qxjp-p4hr

почти 4 года назад

CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-423c-8p99-7j35

больше 3 лет назад

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take control of the operating system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4239-cmjf-x875

больше 3 лет назад

Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.

EPSS: Низкий
github логотип

GHSA-4239-64c9-rvg2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-4238-47vc-27hv

почти 4 года назад

Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."

EPSS: Низкий
github логотип

GHSA-4236-7hj3-75v7

больше 3 лет назад

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). The supported version that is affected is Java SE: 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4236-36gg-25m7

больше 3 лет назад

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4235-rv3m-2xwx

больше 3 лет назад

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4233-qhc3-4437

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4233-7q5q-m7p6

около 2 лет назад

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4233-4643-92j7

больше 3 лет назад

Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4232-hhhx-rgv2

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function.

EPSS: Низкий
github логотип

GHSA-422w-cq3x-prq2

почти 4 года назад

SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-423j-38qf-whqh

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225347.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-423h-q743-cc99

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250562 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-423h-mr5w-x796

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-423h-j3gq-xjw2

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-423h-352x-q557

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-423g-qv8g-mgcc

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of quota, or create an unbounded number of nodes owned by dom0, thus running xenstored out of memory A malicious guest administrator can cause a denial of service against a specific guest or against the whole host. All systems using oxenstored are vulnerable. Building and using oxenstored is the default in the upstream Xen distribution, if the Ocaml compiler is available. Systems using C xenstored are not vulnerable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-423g-mrq6-vpvp

In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 7.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-423c-qxjp-p4hr

CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.

1%
Низкий
почти 4 года назад
github логотип
GHSA-423c-8p99-7j35

Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take control of the operating system.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4239-cmjf-x875

Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4239-64c9-rvg2

Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4238-47vc-27hv

Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."

0%
Низкий
почти 4 года назад
github логотип
GHSA-4236-7hj3-75v7

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). The supported version that is affected is Java SE: 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4236-36gg-25m7

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4235-rv3m-2xwx

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4233-qhc3-4437

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-4233-7q5q-m7p6

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-4233-4643-92j7

Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4232-hhhx-rgv2

Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-422w-cq3x-prq2

SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу