Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-28mh-f3rj-cr4f

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.

EPSS: Низкий
github логотип

GHSA-28mg-g72w-qrh2

больше 2 лет назад

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-28mg-98xm-q493

больше 3 лет назад

Open Redirect in archivy

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28mg-8v5c-567h

почти 2 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28mf-xh5q-4rgc

около 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-28mf-w32g-rfg3

около 3 лет назад

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28mc-jvx2-g85v

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: require cloned buffers to share accounting contexts When IORING_REGISTER_CLONE_BUFFERS is used to clone buffers from uring instance A to uring instance B, where A and B use different MMs for accounting, the accounting can go wrong: If uring instance A is closed before uring instance B, the pinned memory counters for uring instance B will be decremented, even though the pinned memory was originally accounted through uring instance A; so the MM of uring instance B can end up with negative locked memory.

EPSS: Низкий
github логотип

GHSA-28mc-g557-92m7

около 1 года назад

@75lb/deep-merge Prototype Pollution vulnerability

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-28mc-4879-xh6f

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.

EPSS: Низкий
github логотип

GHSA-28m9-pp55-859p

больше 3 лет назад

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28m9-8pxg-9chc

больше 3 лет назад

JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.

EPSS: Низкий
github логотип

GHSA-28m9-57g2-hv97

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28m8-h598-2jf6

около 3 лет назад

A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.

EPSS: Низкий
github логотип

GHSA-28m8-9j7v-x499

почти 3 года назад

Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-28m7-9rvj-93mc

больше 2 лет назад

A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-28m7-4v8p-7j37

около 3 лет назад

An information disclosure issue exists in henriquedornas 5.2.17 because an attacker can dump phpMyAdmin SQL content.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28m5-rq67-v9jp

больше 3 лет назад

Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.

EPSS: Низкий
github логотип

GHSA-28m4-r2xf-gjj6

больше 3 лет назад

Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

EPSS: Низкий
github логотип

GHSA-28m4-cx3f-5hh7

больше 3 лет назад

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV starting at image00000000_00400000+0x000000000001b72a."

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28m4-49gg-78fx

3 месяца назад

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28mh-f3rj-cr4f

Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28mg-g72w-qrh2

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28mg-98xm-q493

Open Redirect in archivy

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28mg-8v5c-567h

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-28mf-xh5q-4rgc

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Lazy Social Comments plugin <= 2.0.4 versions.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-28mf-w32g-rfg3

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-28mc-jvx2-g85v

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: require cloned buffers to share accounting contexts When IORING_REGISTER_CLONE_BUFFERS is used to clone buffers from uring instance A to uring instance B, where A and B use different MMs for accounting, the accounting can go wrong: If uring instance A is closed before uring instance B, the pinned memory counters for uring instance B will be decremented, even though the pinned memory was originally accounted through uring instance A; so the MM of uring instance B can end up with negative locked memory.

6 месяцев назад
github логотип
GHSA-28mc-g557-92m7

@75lb/deep-merge Prototype Pollution vulnerability

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-28mc-4879-xh6f

Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28m9-pp55-859p

All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28m9-8pxg-9chc

JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28m9-57g2-hv97

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-28m8-h598-2jf6

A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28m8-9j7v-x499

Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links

CVSS3: 5.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-28m7-9rvj-93mc

A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28m7-4v8p-7j37

An information disclosure issue exists in henriquedornas 5.2.17 because an attacker can dump phpMyAdmin SQL content.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-28m5-rq67-v9jp

Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28m4-r2xf-gjj6

Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28m4-cx3f-5hh7

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV starting at image00000000_00400000+0x000000000001b72a."

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28m4-49gg-78fx

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу