Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 064

Количество 290 064

github логотип

GHSA-2cm6-99q5-hwcr

больше 3 лет назад

dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-2cm6-65p3-5c5j

больше 3 лет назад

An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2cm5-x5xw-8ggq

больше 3 лет назад

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2cm5-f78c-h2c8

больше 3 лет назад

Missing permission checks in Jenkins Distributed Fork Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2cm4-w9vc-vwpc

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

EPSS: Низкий
github логотип

GHSA-2cm4-jmfv-qqw5

больше 3 лет назад

Directory traversal vulnerability in CGI RESCUE KanniBBS2000 (aka KanniBBS2000i, MiniBBS2000, and MiniBBS2000i) before 1.03 allows remote attackers to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2cm4-gp34-f42x

больше 2 лет назад

In gpu drm, there is a possible stack overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363501; Issue ID: ALPS07363501.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2cm3-jjvm-h45g

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cm3-h7wr-fg9v

около 3 лет назад

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

EPSS: Низкий
github логотип

GHSA-2cm3-5rf2-6c3w

больше 3 лет назад

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cm2-g7rj-23f2

около 2 лет назад

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cm2-8q39-h9qp

около 1 года назад

In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjx-jpg9-5gqm

11 месяцев назад

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2cjx-f7xp-2h42

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the data-export feature in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-7267.

EPSS: Низкий
github логотип

GHSA-2cjv-x29w-r6rm

12 месяцев назад

A vulnerability, which was classified as problematic, was found in SourceCodester Record Management System 1.0. This affects an unknown part of the file sort1_user.php. The manipulation of the argument position leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2cjr-qx2h-9vmq

7 месяцев назад

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2cjq-gpfr-mw4c

около 3 лет назад

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cjq-7pqj-grxv

больше 3 лет назад

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

EPSS: Низкий
github логотип

GHSA-2cjm-v4mj-6gvh

около 1 года назад

AndServer 2.1.12 is vulnerable to Directory Traversal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cjm-p78p-rjpj

почти 4 года назад

Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cm6-99q5-hwcr

dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm6-65p3-5c5j

An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm5-x5xw-8ggq

IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm5-f78c-h2c8

Missing permission checks in Jenkins Distributed Fork Plugin

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm4-w9vc-vwpc

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm4-jmfv-qqw5

Directory traversal vulnerability in CGI RESCUE KanniBBS2000 (aka KanniBBS2000i, MiniBBS2000, and MiniBBS2000i) before 1.03 allows remote attackers to read arbitrary files via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm4-gp34-f42x

In gpu drm, there is a possible stack overflow due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363501; Issue ID: ALPS07363501.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cm3-jjvm-h45g

Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2cm3-h7wr-fg9v

This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

1%
Низкий
около 3 лет назад
github логотип
GHSA-2cm3-5rf2-6c3w

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2cm2-g7rj-23f2

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2cm2-8q39-h9qp

In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2cjx-jpg9-5gqm

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants.

CVSS3: 8.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-2cjx-f7xp-2h42

Cross-site scripting (XSS) vulnerability in the data-export feature in the Ricksoft WBS Gantt-Chart add-on 7.8.1 and earlier for JIRA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-7267.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjv-x29w-r6rm

A vulnerability, which was classified as problematic, was found in SourceCodester Record Management System 1.0. This affects an unknown part of the file sort1_user.php. The manipulation of the argument position leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2cjr-qx2h-9vmq

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

CVSS3: 4.7
1%
Низкий
7 месяцев назад
github логотип
GHSA-2cjq-gpfr-mw4c

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2cjq-7pqj-grxv

rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjm-v4mj-6gvh

AndServer 2.1.12 is vulnerable to Directory Traversal.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-2cjm-p78p-rjpj

Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
2%
Низкий
почти 4 года назад

Уязвимостей на страницу