Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3r8g-564w-2jq8

почти 4 года назад

PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[AdminPath] parameter.

EPSS: Низкий
github логотип

GHSA-3r8f-gphx-9m2c

больше 7 лет назад

Path Traversal in mcstatic

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3r8f-fqj5-97x5

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter to (1) bb_func_forums.php, (2) bb_functions.php, or (3) the RSS plugin.

EPSS: Низкий
github логотип

GHSA-3r8c-x2gq-vxw3

почти 4 года назад

Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted (1) AAC or (2) MP3 file, as demonstrated by a ringtone with malformed entries in the sample size table.

EPSS: Низкий
github логотип

GHSA-3r8c-rqqr-c7h4

больше 3 лет назад

An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3r8c-j3rv-xw2p

больше 3 лет назад

The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remote attackers to obtain access to certain entityforms via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3r89-8m76-vxrv

больше 3 лет назад

Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3r89-8hw3-86vc

около 4 лет назад

The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r89-7qf6-h2m8

больше 3 лет назад

SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

EPSS: Низкий
github логотип

GHSA-3r87-cgc8-24q7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.

EPSS: Низкий
github логотип

GHSA-3r87-7296-4j6w

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3r87-4xwq-xh86

3 месяца назад

Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3r86-xc8x-m6c4

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3r86-pp9h-4fh6

больше 3 лет назад

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r86-94r4-7mg9

2 месяца назад

In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4820.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r85-3gpw-c7mc

почти 4 года назад

An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3r84-hhrv-2935

больше 2 лет назад

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r84-frqg-8226

почти 4 года назад

The WooCommerce WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

EPSS: Низкий
github логотип

GHSA-3r84-39rf-qwh3

больше 3 лет назад

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3r84-3353-c3qj

больше 3 лет назад

Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r8g-564w-2jq8

PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[AdminPath] parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3r8f-gphx-9m2c

Path Traversal in mcstatic

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-3r8f-fqj5-97x5

Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter to (1) bb_func_forums.php, (2) bb_functions.php, or (3) the RSS plugin.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r8c-x2gq-vxw3

Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted (1) AAC or (2) MP3 file, as demonstrated by a ringtone with malformed entries in the sample size table.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3r8c-rqqr-c7h4

An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r8c-j3rv-xw2p

The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remote attackers to obtain access to certain entityforms via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r89-8m76-vxrv

Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r89-8hw3-86vc

The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration settings.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3r89-7qf6-h2m8

SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r87-cgc8-24q7

Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r87-7296-4j6w

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r87-4xwq-xh86

Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3r86-xc8x-m6c4

Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r86-pp9h-4fh6

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r86-94r4-7mg9

In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4820.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3r85-3gpw-c7mc

An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.

CVSS3: 7.2
9%
Низкий
почти 4 года назад
github логотип
GHSA-3r84-hhrv-2935

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3r84-frqg-8226

The WooCommerce WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r84-39rf-qwh3

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r84-3353-c3qj

Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу