Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 436

Количество 289 436

github логотип

GHSA-2954-4rrv-2pfp

4 месяца назад

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2952-j2hp-678j

больше 1 года назад

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2952-9pxc-jw5m

больше 3 лет назад

SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

EPSS: Низкий
github логотип

GHSA-294x-x7jx-8864

4 месяца назад

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-294x-vx6v-6x6f

около 3 лет назад

vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-294x-pcj2-wqf8

около 1 года назад

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-294x-mfp7-qj66

около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-294x-cxhp-6h86

около 3 лет назад

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-294x-8m55-rc5p

больше 3 лет назад

Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.

EPSS: Низкий
github логотип

GHSA-294x-764g-q87f

больше 3 лет назад

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-294x-3cw7-9wh8

больше 3 лет назад

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-294w-jfj8-gx6r

больше 3 лет назад

Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.

EPSS: Низкий
github логотип

GHSA-294v-8cm4-5x8q

около 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.

EPSS: Низкий
github логотип

GHSA-294r-xq83-57q9

около 3 лет назад

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-294r-c888-mvp7

около 3 лет назад

An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-294r-867g-x8h5

около 3 лет назад

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-294r-4892-r6wr

больше 3 лет назад

md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-294q-5vvf-xj65

около 1 года назад

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-294q-4ffj-cf8j

около 3 лет назад

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-294m-6544-vprq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2954-4rrv-2pfp

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2952-j2hp-678j

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2952-9pxc-jw5m

SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-294x-x7jx-8864

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-294x-vx6v-6x6f

vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-294x-pcj2-wqf8

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

CVSS3: 9.4
1%
Низкий
около 1 года назад
github логотип
GHSA-294x-mfp7-qj66

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-294x-cxhp-6h86

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-294x-8m55-rc5p

Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-294x-764g-q87f

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-294x-3cw7-9wh8

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-294w-jfj8-gx6r

Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-294v-8cm4-5x8q

Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-294r-xq83-57q9

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-294r-c888-mvp7

An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-294r-867g-x8h5

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2%
Низкий
около 3 лет назад
github логотип
GHSA-294r-4892-r6wr

md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-294q-5vvf-xj65

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVSS3: 7.5
91%
Критический
около 1 года назад
github логотип
GHSA-294q-4ffj-cf8j

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-294m-6544-vprq

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу