Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3x47-pxw6-fmvq

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x47-j85r-45r9

почти 4 года назад

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x47-hh2w-gf29

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-vw5g-qxj4

почти 4 года назад

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

EPSS: Низкий
github логотип

GHSA-3x46-hg82-953f

больше 3 лет назад

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x46-fhq4-2cp2

почти 3 года назад

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x46-c2g7-344x

почти 2 года назад

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3x46-6xw6-vv9h

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-395m-v3qc

почти 3 года назад

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x46-2jq5-628v

больше 3 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

EPSS: Средний
github логотип

GHSA-3x45-j72c-xqpj

больше 1 года назад

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3x44-c8w2-mxwg

больше 3 лет назад

The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3x44-884c-cc67

3 месяца назад

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x43-9cxq-4fwr

почти 4 года назад

The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.

EPSS: Низкий
github логотип

GHSA-3x43-8h7p-m97w

больше 3 лет назад

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x42-vgc3-7f6c

больше 3 лет назад

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x3x-vjcr-56cc

больше 2 лет назад

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x3x-gvp4-q59h

больше 3 лет назад

SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x3x-fgf2-hxxv

больше 3 лет назад

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.

EPSS: Низкий
github логотип

GHSA-3x3w-vcjx-7796

больше 3 лет назад

Cross-Site Request Forgery in easyii CMS

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x47-pxw6-fmvq

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3x47-j85r-45r9

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3x47-hh2w-gf29

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-3x46-vw5g-qxj4

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x46-hg82-953f

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x46-fhq4-2cp2

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x46-c2g7-344x

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
19%
Средний
почти 2 года назад
github логотип
GHSA-3x46-6xw6-vv9h

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-3x46-395m-v3qc

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x46-2jq5-628v

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

47%
Средний
больше 3 лет назад
github логотип
GHSA-3x45-j72c-xqpj

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x44-c8w2-mxwg

The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.

CVSS3: 6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x44-884c-cc67

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3x43-9cxq-4fwr

The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3x43-8h7p-m97w

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x42-vgc3-7f6c

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3x-vjcr-56cc

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x3x-gvp4-q59h

SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3x-fgf2-hxxv

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3w-vcjx-7796

Cross-Site Request Forgery in easyii CMS

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу