Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 543

Количество 289 543

github логотип

GHSA-27v9-jf76-68p4

почти 2 года назад

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27v9-6wwc-82r3

около 3 лет назад

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-27v9-58mg-8v43

около 3 лет назад

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

EPSS: Низкий
github логотип

GHSA-27v7-qhfv-rqq8

около 6 лет назад

Insecure Credential Storage in web3

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-27v6-gmmm-5qf3

больше 3 лет назад

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

EPSS: Низкий
github логотип

GHSA-27v6-4m9p-3qq4

почти 3 года назад

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27v5-v9w4-6pr5

больше 3 лет назад

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27v5-q384-ff55

больше 3 лет назад

find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.

EPSS: Низкий
github логотип

GHSA-27v4-w7r4-68vg

больше 1 года назад

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-27v4-m256-2g57

почти 2 года назад

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-27v4-jvv2-r77h

больше 3 лет назад

SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

EPSS: Низкий
github логотип

GHSA-27v4-h6gj-f3w5

больше 3 лет назад

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-27v4-cjp2-mwc4

больше 3 лет назад

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.

EPSS: Низкий
github логотип

GHSA-27v4-8jv4-3cp6

около 3 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-27v4-4p5h-63xx

около 3 лет назад

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

EPSS: Низкий
github логотип

GHSA-27v3-wp78-r8ww

больше 3 лет назад

When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27v3-j68w-q6ph

больше 3 лет назад

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-27v2-398x-f74x

больше 3 лет назад

MAGMI cross-site scripting (XSS)

EPSS: Низкий
github логотип

GHSA-27rx-wrqr-qj3v

больше 3 лет назад

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

EPSS: Низкий
github логотип

GHSA-27rx-w643-mrjg

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27v9-jf76-68p4

A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239260.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-27v9-6wwc-82r3

Possible out of bound read due to improper validation of certificate chain in SSL or Internet key exchange in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-27v9-58mg-8v43

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27v7-qhfv-rqq8

Insecure Credential Storage in web3

CVSS3: 3.3
около 6 лет назад
github логотип
GHSA-27v6-gmmm-5qf3

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-27v6-4m9p-3qq4

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

CVSS3: 7.2
3%
Низкий
почти 3 года назад
github логотип
GHSA-27v5-v9w4-6pr5

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v5-q384-ff55

find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v4-w7r4-68vg

Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-27v4-m256-2g57

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVSS3: 9.8
13%
Средний
почти 2 года назад
github логотип
GHSA-27v4-jvv2-r77h

SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27v4-h6gj-f3w5

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v4-cjp2-mwc4

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v4-8jv4-3cp6

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

0%
Низкий
около 3 лет назад
github логотип
GHSA-27v4-4p5h-63xx

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27v3-wp78-r8ww

When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v3-j68w-q6ph

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27v2-398x-f74x

MAGMI cross-site scripting (XSS)

5%
Низкий
больше 3 лет назад
github логотип
GHSA-27rx-wrqr-qj3v

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27rx-w643-mrjg

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу