Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 292 001

Количество 292 001

github логотип

GHSA-2hw7-mxvj-m455

больше 4 лет назад

Path traversal in Node-RED-Dashboard

EPSS: Высокий
github логотип

GHSA-2hw7-5qc9-q2cg

больше 3 лет назад

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

EPSS: Низкий
github логотип

GHSA-2hw7-485w-9j23

больше 3 лет назад

WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.

EPSS: Низкий
github логотип

GHSA-2hw6-6rgf-726v

больше 3 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hw6-6573-fv43

4 дня назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw6-4rv9-82fp

больше 2 лет назад

Uvdesk remote code execution vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hw5-wx32-97v6

больше 3 лет назад

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

EPSS: Низкий
github логотип

GHSA-2hw5-388c-g7xj

больше 3 лет назад

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-wmq2-hxf7

больше 3 лет назад

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hw3-h8qx-hqqp

3 месяца назад

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-28v7-q78p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

EPSS: Средний
github логотип

GHSA-2hw2-h3mf-c2j9

больше 3 лет назад

Moodle open redirect vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2hw2-7jq8-w9vp

больше 3 лет назад

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

EPSS: Средний
github логотип

GHSA-2hw2-62cp-p9p7

больше 6 лет назад

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hvx-m86j-h9m3

больше 3 лет назад

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

EPSS: Средний
github логотип

GHSA-2hvx-9r8j-qvph

около 2 лет назад

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvx-93c2-p928

почти 2 года назад

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2hvw-r4rp-mjpp

около 2 лет назад

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hvv-h4pw-wcm2

больше 3 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

EPSS: Низкий
github логотип

GHSA-2hvr-h6gw-qrxp

почти 3 года назад

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hw7-mxvj-m455

Path traversal in Node-RED-Dashboard

89%
Высокий
больше 4 лет назад
github логотип
GHSA-2hw7-5qc9-q2cg

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw7-485w-9j23

WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw6-6rgf-726v

Moodle XSS Vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw6-6573-fv43

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows Stored XSS. This issue affects WP Delicious: from n/a through 1.8.7.

CVSS3: 6.5
0%
Низкий
4 дня назад
github логотип
GHSA-2hw6-4rv9-82fp

Uvdesk remote code execution vulnerability

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hw5-wx32-97v6

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw5-388c-g7xj

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw3-wmq2-hxf7

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw3-h8qx-hqqp

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2hw3-28v7-q78p

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

48%
Средний
больше 3 лет назад
github логотип
GHSA-2hw2-h3mf-c2j9

Moodle open redirect vulnerability

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw2-7jq8-w9vp

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

70%
Средний
больше 3 лет назад
github логотип
GHSA-2hw2-62cp-p9p7

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
0%
Низкий
больше 6 лет назад
github логотип
GHSA-2hvx-m86j-h9m3

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

13%
Средний
больше 3 лет назад
github логотип
GHSA-2hvx-9r8j-qvph

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2hvx-93c2-p928

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-2hvw-r4rp-mjpp

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-2hvv-h4pw-wcm2

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvr-h6gw-qrxp

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
0%
Низкий
почти 3 года назад

Уязвимостей на страницу