Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3w9c-7hfp-qxrc

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3w9c-6884-377r

больше 3 лет назад

The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.

EPSS: Низкий
github логотип

GHSA-3w99-q2jm-p4jj

почти 4 года назад

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

EPSS: Низкий
github логотип

GHSA-3w99-p52w-wfq4

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

EPSS: Низкий
github логотип

GHSA-3w99-gx9w-vc94

больше 2 лет назад

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Высокий
github логотип

GHSA-3w99-5f2g-rxfc

больше 2 лет назад

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w98-hgq4-9vr4

больше 3 лет назад

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w97-v426-7jw9

6 месяцев назад

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

EPSS: Средний
github логотип

GHSA-3w97-prq2-5cjc

больше 3 лет назад

Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w97-9v6v-7c57

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability in Brocade Fabric OS versions v7.4.1b and v7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions v7.4.1.x and v7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life Publish report.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w97-3qww-vxj8

больше 3 лет назад

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-3w96-rhq8-qmh8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3w96-p6vh-c298

почти 3 года назад

Cross-site Scripting in pimcore

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3w96-9326-4rfg

больше 3 лет назад

Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w96-2pj9-mfjc

больше 3 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.

EPSS: Низкий
github логотип

GHSA-3w95-jpf5-784j

10 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w95-fv8q-2wr8

около 2 лет назад

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3w95-9p64-7q7q

почти 4 года назад

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

EPSS: Низкий
github логотип

GHSA-3w95-9g93-92fj

больше 2 лет назад

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3w95-95fc-gjxf

почти 4 года назад

SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w9c-7hfp-qxrc

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w9c-6884-377r

The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w99-q2jm-p4jj

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3w99-p52w-wfq4

Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3w99-gx9w-vc94

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
77%
Высокий
больше 2 лет назад
github логотип
GHSA-3w99-5f2g-rxfc

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w98-hgq4-9vr4

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3w97-v426-7jw9

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

67%
Средний
6 месяцев назад
github логотип
GHSA-3w97-prq2-5cjc

Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w97-9v6v-7c57

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability in Brocade Fabric OS versions v7.4.1b and v7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions v7.4.1.x and v7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life Publish report.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w97-3qww-vxj8

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w96-rhq8-qmh8

Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3w96-p6vh-c298

Cross-site Scripting in pimcore

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3w96-9326-4rfg

Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3w96-2pj9-mfjc

An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w95-jpf5-784j

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3w95-fv8q-2wr8

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVSS3: 7.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3w95-9p64-7q7q

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3w95-9g93-92fj

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w95-95fc-gjxf

SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу