Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wxv-wgwg-qwjr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.

EPSS: Низкий
github логотип

GHSA-3wxv-vvvq-84p8

почти 4 года назад

Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wxv-m6v8-9vx3

больше 3 лет назад

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

EPSS: Низкий
github логотип

GHSA-3wxv-8cx4-wg98

больше 3 лет назад

Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is unauthenticated.

EPSS: Низкий
github логотип

GHSA-3wxq-grgm-m8r3

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emraan Cheema CubeWP allows Stored XSS. This issue affects CubeWP: from n/a through 1.1.26.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wxq-7r8m-qpmg

больше 7 лет назад

ffmepg is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wxq-76w9-ghcp

около 2 лет назад

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-3wxp-gf5c-jh8g

больше 3 лет назад

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3wxp-8m6g-m8x5

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core hub-core allows PHP Local File Inclusion.This issue affects Hub Core: from n/a through <= 5.0.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wxp-8cgp-vmq4

больше 3 лет назад

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wxm-m9m4-cprj

больше 4 лет назад

Import of incorrectly embargoed keys could cause early publication

EPSS: Низкий
github логотип

GHSA-3wxm-9mxw-85q8

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-3wxj-wj2j-9jpg

около 2 лет назад

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3wxj-rr25-288c

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: usb: typec: wusb3801: fix fwnode refcount leak in wusb3801_probe() I got the following report while doing fault injection test: OF: ERROR: memory leak, expected refcount 1 instead of 4, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/tcpc@60/connector If wusb3801_hw_init() fails, fwnode_handle_put() needs be called to avoid refcount leak.

EPSS: Низкий
github логотип

GHSA-3wxj-j5hp-5gfc

почти 4 года назад

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

EPSS: Средний
github логотип

GHSA-3wxj-9hw9-r4p8

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ProjeQtOr (formerly Project'Or RIA) before 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to view/parameter.php, (2) p1value parameter to view/main.php, or (3) objectClass parameter to view/objectDetail.php.

EPSS: Низкий
github логотип

GHSA-3wxh-43c2-qm9r

больше 3 лет назад

In NatHack between 3.6.0 and 3.6.3, a buffer overflow issue exists when reading very long lines from a NetHack configuration file (usually named .nethackrc). This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. All users are urged to upgrade to NetHack 3.6.4 as soon as possible.

EPSS: Низкий
github логотип

GHSA-3wxg-w96j-8hq9

больше 2 лет назад

CraftCMS stored XSS in Quick Post widget error message

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3wxg-vvf7-x9pf

больше 3 лет назад

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-3wxg-g674-g9ph

почти 3 года назад

A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /adms/admin/?page=vehicles/view_transaction. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221481 was assigned to this vulnerability.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wxv-wgwg-qwjr

Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wxv-vvvq-84p8

Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3wxv-m6v8-9vx3

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3wxv-8cx4-wg98

Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly Local Management mode, have a vulnerability in the remote firmware download feature that could allow a user to place or replace an arbitrary file on the remote host. In non-secure mode, the user is unauthenticated.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wxq-grgm-m8r3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emraan Cheema CubeWP allows Stored XSS. This issue affects CubeWP: from n/a through 1.1.26.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3wxq-7r8m-qpmg

ffmepg is malware

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-3wxq-76w9-ghcp

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

CVSS3: 2.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wxp-gf5c-jh8g

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

CVSS3: 7.8
17%
Средний
больше 3 лет назад
github логотип
GHSA-3wxp-8m6g-m8x5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core hub-core allows PHP Local File Inclusion.This issue affects Hub Core: from n/a through <= 5.0.8.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3wxp-8cgp-vmq4

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

CVSS3: 7.5
9%
Низкий
больше 3 лет назад
github логотип
GHSA-3wxm-m9m4-cprj

Import of incorrectly embargoed keys could cause early publication

больше 4 лет назад
github логотип
GHSA-3wxm-9mxw-85q8

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wxj-wj2j-9jpg

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

CVSS3: 4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wxj-rr25-288c

In the Linux kernel, the following vulnerability has been resolved: usb: typec: wusb3801: fix fwnode refcount leak in wusb3801_probe() I got the following report while doing fault injection test: OF: ERROR: memory leak, expected refcount 1 instead of 4, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/tcpc@60/connector If wusb3801_hw_init() fails, fwnode_handle_put() needs be called to avoid refcount leak.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wxj-j5hp-5gfc

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

28%
Средний
почти 4 года назад
github логотип
GHSA-3wxj-9hw9-r4p8

Multiple cross-site scripting (XSS) vulnerabilities in ProjeQtOr (formerly Project'Or RIA) before 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to view/parameter.php, (2) p1value parameter to view/main.php, or (3) objectClass parameter to view/objectDetail.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wxh-43c2-qm9r

In NatHack between 3.6.0 and 3.6.3, a buffer overflow issue exists when reading very long lines from a NetHack configuration file (usually named .nethackrc). This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. All users are urged to upgrade to NetHack 3.6.4 as soon as possible.

больше 3 лет назад
github логотип
GHSA-3wxg-w96j-8hq9

CraftCMS stored XSS in Quick Post widget error message

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wxg-vvf7-x9pf

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

CVSS3: 7.2
74%
Высокий
больше 3 лет назад
github логотип
GHSA-3wxg-g674-g9ph

A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /adms/admin/?page=vehicles/view_transaction. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221481 was assigned to this vulnerability.

CVSS3: 8.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу