Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3w73-4p4p-f992

почти 4 года назад

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w6x-xqhx-2c63

около 2 месяцев назад

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3w6x-jcm9-p8w3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail In case of region creation fail in ipc_devlink_create_region(), previously created regions delete process starts from tainted pointer which actually holds error code value. Fix this bug by decreasing region index before delete. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3w6x-j894-mcx4

около 1 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS.This issue affects Custom Post Status: from n/a through 1.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3w6x-g2w9-f5ph

почти 4 года назад

Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.

EPSS: Низкий
github логотип

GHSA-3w6w-r9vq-3r79

около 2 лет назад

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w6w-q6rh-xhgj

около 2 лет назад

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w6w-26ch-mqc9

почти 4 года назад

SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.

EPSS: Низкий
github логотип

GHSA-3w6v-h5wr-h9rh

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w6v-5j67-jj7h

около 2 лет назад

An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w6q-rqw9-h6qx

3 месяца назад

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3w6q-chqr-4j8j

больше 3 лет назад

MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

EPSS: Низкий
github логотип

GHSA-3w6q-cgc3-v6vv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

EPSS: Средний
github логотип

GHSA-3w6p-qff7-qc9f

больше 3 лет назад

EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3w6p-8f82-gw8r

около 4 лет назад

Using JMSAppender in log4j configuration may lead to deserialization of untrusted data

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3w6m-x2x7-982w

почти 4 года назад

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3w6m-h87r-x45q

около 1 года назад

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3w6m-fc8w-97c4

почти 4 года назад

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

EPSS: Низкий
github логотип

GHSA-3w6j-gj2m-vh4c

больше 3 лет назад

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

EPSS: Низкий
github логотип

GHSA-3w6j-f4xj-hmhr

около 3 лет назад

xpdfreader 4.03 is vulnerable to Buffer Overflow.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w73-4p4p-f992

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3w6x-xqhx-2c63

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

CVSS3: 6.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3w6x-jcm9-p8w3

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail In case of region creation fail in ipc_devlink_create_region(), previously created regions delete process starts from tainted pointer which actually holds error code value. Fix this bug by decreasing region index before delete. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3w6x-j894-mcx4

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS.This issue affects Custom Post Status: from n/a through 1.1.0.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3w6x-g2w9-f5ph

Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3w6w-r9vq-3r79

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3w6w-q6rh-xhgj

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
8%
Низкий
около 2 лет назад
github логотип
GHSA-3w6w-26ch-mqc9

SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3w6v-h5wr-h9rh

Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w6v-5j67-jj7h

An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3w6q-rqw9-h6qx

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).

CVSS3: 3.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3w6q-chqr-4j8j

MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w6q-cgc3-v6vv

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

18%
Средний
больше 3 лет назад
github логотип
GHSA-3w6p-qff7-qc9f

EMC RSA Data Loss Prevention (DLP) 9.x before 9.6-SP2 does not properly manage sessions, which allows remote authenticated users to gain privileges and bypass intended content-reading restrictions via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w6p-8f82-gw8r

Using JMSAppender in log4j configuration may lead to deserialization of untrusted data

CVSS3: 8.1
около 4 лет назад
github логотип
GHSA-3w6m-x2x7-982w

Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3w6m-h87r-x45q

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3w6m-fc8w-97c4

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3w6j-gj2m-vh4c

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w6j-f4xj-hmhr

xpdfreader 4.03 is vulnerable to Buffer Overflow.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу