Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-27w2-xhhr-rp5p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

EPSS: Низкий
github логотип

GHSA-27w2-gfcm-69mr

около 2 лет назад

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-27vx-r33r-rh7x

больше 3 лет назад

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27vr-8fpq-79vm

больше 3 лет назад

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27vr-69mf-gx49

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

EPSS: Низкий
github логотип

GHSA-27vr-5h5p-w59c

2 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27vr-24cc-98h4

больше 1 года назад

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-27vq-mhjm-v9gc

больше 3 лет назад

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27vq-hv74-7cqp

8 месяцев назад

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

EPSS: Низкий
github логотип

GHSA-27vq-c7q6-wxpx

больше 3 лет назад

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

EPSS: Низкий
github логотип

GHSA-27vp-6288-jjwg

около 1 года назад

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27vm-9gw5-232w

больше 3 лет назад

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27vh-hwmj-r5gc

больше 3 лет назад

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-27vh-h6mc-q6g8

10 месяцев назад

btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27vh-g9xh-6mc8

около 3 лет назад

In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27vh-g29g-4cf7

20 дней назад

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27vg-xj68-r4p8

около 3 лет назад

An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27vg-v28w-gqgh

около 3 лет назад

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-27vg-qjpq-w479

10 месяцев назад

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-27vg-mg2m-7qv2

больше 3 лет назад

In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27w2-xhhr-rp5p

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w2-gfcm-69mr

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-27vx-r33r-rh7x

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-8fpq-79vm

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-69mf-gx49

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-5h5p-w59c

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-27vr-24cc-98h4

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-27vq-mhjm-v9gc

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vq-hv74-7cqp

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

8 месяцев назад
github логотип
GHSA-27vq-c7q6-wxpx

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vp-6288-jjwg

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVSS3: 7.5
2%
Низкий
около 1 года назад
github логотип
GHSA-27vm-9gw5-232w

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vh-hwmj-r5gc

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vh-h6mc-q6g8

btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

CVSS3: 7.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-27vh-g9xh-6mc8

In versions 15.0.0-15.1.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, the BIG-IP Server SSL profile ignores revoked certificates, even when a valid CRL is present. This impacts server-side connections and may result in a man-in-the-middle attack on the connections.

CVSS3: 7.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-27vh-g29g-4cf7

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
0%
Низкий
20 дней назад
github логотип
GHSA-27vg-xj68-r4p8

An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-27vg-v28w-gqgh

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.

CVSS3: 9.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-27vg-qjpq-w479

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-27vg-mg2m-7qv2

In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-62679701.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу