Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 844

Количество 290 844

github логотип

GHSA-2g6r-mhp9-27w3

больше 3 лет назад

PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2g6p-p8r8-fqpm

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters.

EPSS: Низкий
github логотип

GHSA-2g6p-35qg-p778

больше 3 лет назад

An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).

EPSS: Низкий
github логотип

GHSA-2g6j-8hm3-67hp

3 месяца назад

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g6h-x254-rxr5

больше 3 лет назад

Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415.

EPSS: Низкий
github логотип

GHSA-2g6h-frv7-55w8

больше 3 лет назад

A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion sensor processing. This issue is fixed in iOS 12.2, watchOS 5.2. A malicious app may be able to track users between installs.

EPSS: Низкий
github логотип

GHSA-2g6g-pm4c-vj6c

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion plugin <= 2.6 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2g6g-hhqw-63q5

4 месяца назад

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g6g-729w-5726

больше 3 лет назад

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access protected information, which may lead to information disclosure.

EPSS: Низкий
github логотип

GHSA-2g6c-r55g-m734

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides the platform_data. The following log reveals it: [ 29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40 [ 29.610730] Read of size 40 at addr 0000000000000000 by task bash/414 [ 29.612820] Call Trace: [ 29.613030] <TASK> [ 29.613201] dump_stack_lvl+0x56/0x6f [ 29.613496] ? kmemdup+0x30/0x40 [ 29.613754] print_report.cold+0x494/0x6b7 [ 29.614082] ? kmemdup+0x30/0x40 [ 29.614340] kasan_report+0x8a/0x190 [ 29.614628] ? kmemdup+0x30/0x40 [ 29.614888] kasan_check_range+0x14d/0x1d0 [ 29.615213] memcpy+0x20/0x60 [ 29.615454] kmemdup+0x30/0x40 [ 29.615700] lgdt3306a_probe+0x52/0x310 [ 29.616339] i2c_device_probe+0x951/0xa90

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g6c-q924-h63h

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.

EPSS: Низкий
github логотип

GHSA-2g6c-2vm9-2g8p

11 месяцев назад

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g69-fwvg-7wfv

больше 3 лет назад

PHP Easy Download allows remote attackers to bypass authentication via edit.php.

EPSS: Низкий
github логотип

GHSA-2g69-35m2-8pf5

больше 3 лет назад

Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4299, CVE-2014-4300, CVE-2014-6452, and CVE-2014-6542.

EPSS: Низкий
github логотип

GHSA-2g68-q4wg-9q24

больше 3 лет назад

Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2g68-c3qc-8985

больше 1 года назад

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g67-jw5m-244m

больше 2 лет назад

sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated string representation of a number, if the buffer is allocated the exact size required to represent that number as a string. For example, 1,234,567 (with padding to 13) overflows by two bytes.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g67-cxmx-v5g5

больше 3 лет назад

Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.

EPSS: Низкий
github логотип

GHSA-2g67-9vpf-54rq

почти 3 года назад

The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g66-93q3-jx9r

больше 3 лет назад

Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g6r-mhp9-27w3

PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.

CVSS3: 7.2
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6p-p8r8-fqpm

Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6p-35qg-p778

An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6j-8hm3-67hp

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2g6h-x254-rxr5

Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6h-frv7-55w8

A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion sensor processing. This issue is fixed in iOS 12.2, watchOS 5.2. A malicious app may be able to track users between installs.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6g-pm4c-vj6c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion plugin <= 2.6 versions.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g6g-hhqw-63q5

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2g6g-729w-5726

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access protected information, which may lead to information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6c-r55g-m734

In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides the platform_data. The following log reveals it: [ 29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40 [ 29.610730] Read of size 40 at addr 0000000000000000 by task bash/414 [ 29.612820] Call Trace: [ 29.613030] <TASK> [ 29.613201] dump_stack_lvl+0x56/0x6f [ 29.613496] ? kmemdup+0x30/0x40 [ 29.613754] print_report.cold+0x494/0x6b7 [ 29.614082] ? kmemdup+0x30/0x40 [ 29.614340] kasan_report+0x8a/0x190 [ 29.614628] ? kmemdup+0x30/0x40 [ 29.614888] kasan_check_range+0x14d/0x1d0 [ 29.615213] memcpy+0x20/0x60 [ 29.615454] kmemdup+0x30/0x40 [ 29.615700] lgdt3306a_probe+0x52/0x310 [ 29.616339] i2c_device_probe+0x951/0xa90

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2g6c-q924-h63h

Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2g6c-2vm9-2g8p

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2g69-fwvg-7wfv

PHP Easy Download allows remote attackers to bypass authentication via edit.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g69-35m2-8pf5

Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4299, CVE-2014-4300, CVE-2014-6452, and CVE-2014-6542.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g68-q4wg-9q24

Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g68-c3qc-8985

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g67-jw5m-244m

sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated string representation of a number, if the buffer is allocated the exact size required to represent that number as a string. For example, 1,234,567 (with padding to 13) overflows by two bytes.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g67-cxmx-v5g5

Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g67-9vpf-54rq

The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2g66-93q3-jx9r

Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message.

10%
Низкий
больше 3 лет назад

Уязвимостей на страницу