Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3rpm-wgqm-r264

больше 3 лет назад

Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.

EPSS: Низкий
github логотип

GHSA-3rpm-h4f9-j349

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rpm-6p6h-45fh

больше 3 лет назад

Windows Resilient File System Elevation of Privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rpm-2rjq-r29f

почти 4 года назад

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

EPSS: Низкий
github логотип

GHSA-3rpj-mvwg-494q

больше 3 лет назад

The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

EPSS: Низкий
github логотип

GHSA-3rpj-583g-x22p

больше 3 лет назад

Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network.

EPSS: Низкий
github логотип

GHSA-3rph-v6j3-hfch

почти 4 года назад

Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.

EPSS: Средний
github логотип

GHSA-3rph-pvh6-rj33

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.

EPSS: Низкий
github логотип

GHSA-3rph-74jp-p9fc

больше 3 лет назад

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3rpg-q8jq-cgrc

больше 3 лет назад

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3rpg-mvgw-33wg

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.

EPSS: Низкий
github логотип

GHSA-3rpg-jfvw-x748

больше 3 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

EPSS: Низкий
github логотип

GHSA-3rpg-hvp5-w7r8

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rpf-v574-x42r

почти 4 года назад

** DISPUTED ** Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying "The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We have update our demo version and made sure all those vulnerabilities are fixed."

EPSS: Низкий
github логотип

GHSA-3rpf-hx7x-258c

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-Já Pagamentos for WooCommerce allows Reflected XSS. This issue affects Já-Já Pagamentos for WooCommerce: from n/a through 1.3.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3rpf-5rqv-689q

почти 5 лет назад

PHP Code Injection by malicious function name in smarty

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3rp9-w2c5-r4p5

больше 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

EPSS: Низкий
github логотип

GHSA-3rp8-5q68-6m8w

около 1 года назад

Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24106.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rp7-3qfg-r7f3

около 2 лет назад

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3rp6-rjw4-cq39

больше 3 лет назад

Cross-origin Resource Sharing bypass in ASP.NET Core

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rpm-wgqm-r264

Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpm-h4f9-j349

Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rpm-6p6h-45fh

Windows Resilient File System Elevation of Privilege.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpm-2rjq-r29f

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3rpj-mvwg-494q

The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpj-583g-x22p

Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rph-v6j3-hfch

Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.

27%
Средний
почти 4 года назад
github логотип
GHSA-3rph-pvh6-rj33

Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3rph-74jp-p9fc

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.

CVSS3: 8.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpg-q8jq-cgrc

Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpg-mvgw-33wg

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpg-jfvw-x748

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rpg-hvp5-w7r8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.23.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3rpf-v574-x42r

** DISPUTED ** Multiple SQL injection vulnerabilities in INFINICART allow remote attackers to execute arbitrary SQL commands via the (1) groupid parameter in (a) browse_group.asp, (2) productid parameter in (b) added_to_cart.asp, and (3) catid and (4) subid parameter in (c) browsesubcat.asp. NOTE: the vendor has disputed this report, saying "The vulnerabilities mentioned were never present in our official released products but only in the unofficial demo version. However we do appreciate the information. We have update our demo version and made sure all those vulnerabilities are fixed."

1%
Низкий
почти 4 года назад
github логотип
GHSA-3rpf-hx7x-258c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-Já Pagamentos for WooCommerce allows Reflected XSS. This issue affects Já-Já Pagamentos for WooCommerce: from n/a through 1.3.0.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3rpf-5rqv-689q

PHP Code Injection by malicious function name in smarty

CVSS3: 9.8
76%
Высокий
почти 5 лет назад
github логотип
GHSA-3rp9-w2c5-r4p5

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rp8-5q68-6m8w

Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24106.

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3rp7-3qfg-r7f3

Deserialization of Untrusted Data vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.11.1.

CVSS3: 9.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-3rp6-rjw4-cq39

Cross-origin Resource Sharing bypass in ASP.NET Core

CVSS3: 7.5
11%
Средний
больше 3 лет назад

Уязвимостей на страницу