Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x4g-gq53-pcx7

почти 4 года назад

Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.

EPSS: Низкий
github логотип

GHSA-3x4g-4374-v83h

больше 1 года назад

there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3x4f-24vq-5mhp

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x4c-pq33-4w3q

больше 4 лет назад

Improper authorisation of members discloses room membership to non-members

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x49-p9xf-cg52

почти 4 года назад

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

EPSS: Низкий
github логотип

GHSA-3x49-h2mv-h459

около 1 года назад

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3x49-g6rc-c284

почти 3 года назад

LiteDB may deserialize bad JSON on object type using _type

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x48-c5fq-3p9x

больше 1 года назад

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x48-6948-gjj7

почти 4 года назад

Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

EPSS: Средний
github логотип

GHSA-3x47-w4rx-6pm7

больше 1 года назад

LoLLMS Path Traversal vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x47-pxw6-fmvq

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x47-j85r-45r9

почти 4 года назад

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x47-hh2w-gf29

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-vw5g-qxj4

почти 4 года назад

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

EPSS: Низкий
github логотип

GHSA-3x46-hg82-953f

больше 3 лет назад

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x46-fhq4-2cp2

почти 3 года назад

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x46-c2g7-344x

почти 2 года назад

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3x46-6xw6-vv9h

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3x46-395m-v3qc

почти 3 года назад

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x46-2jq5-628v

больше 3 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x4g-gq53-pcx7

Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x4g-4374-v83h

there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x4f-24vq-5mhp

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x4c-pq33-4w3q

Improper authorisation of members discloses room membership to non-members

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3x49-p9xf-cg52

Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x49-h2mv-h459

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3x49-g6rc-c284

LiteDB may deserialize bad JSON on object type using _type

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3x48-c5fq-3p9x

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted by an Administrator, to create new or edit existing forms, including updating the default registration role to Administrator on User Registration forms.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x48-6948-gjj7

Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

11%
Средний
почти 4 года назад
github логотип
GHSA-3x47-w4rx-6pm7

LoLLMS Path Traversal vulnerability

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x47-pxw6-fmvq

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3x47-j85r-45r9

Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3x47-hh2w-gf29

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-3x46-vw5g-qxj4

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x46-hg82-953f

A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x46-fhq4-2cp2

In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x46-c2g7-344x

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

CVSS3: 8.8
19%
Средний
почти 2 года назад
github логотип
GHSA-3x46-6xw6-vv9h

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-3x46-395m-v3qc

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x46-2jq5-628v

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

47%
Средний
больше 3 лет назад

Уязвимостей на страницу