Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 287 888

Количество 287 888

github логотип

GHSA-23wp-rxm7-f6f3

около 3 лет назад

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23wp-pqh4-8w8f

около 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23wj-wvvj-vgcc

больше 3 лет назад

Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23wj-r557-8c5p

около 3 лет назад

tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23wj-h8fm-chf2

около 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23wj-fq4f-57vr

около 3 лет назад

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23wh-q78v-xxm4

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: tracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit() When trace_get_event_file() failed, gen_kretprobe_test will be assigned as the error code. If module kprobe_event_gen_test is removed now, the null pointer dereference will happen in kprobe_event_gen_test_exit(). Check if gen_kprobe_test or gen_kretprobe_test is error code or NULL before dereference them. BUG: kernel NULL pointer dereference, address: 0000000000000012 PGD 0 P4D 0 Oops: 0000 [#1] SMP PTI CPU: 3 PID: 2210 Comm: modprobe Not tainted 6.1.0-rc1-00171-g2159299a3b74-dirty #217 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014 RIP: 0010:kprobe_event_gen_test_exit+0x1c/0xb5 [kprobe_event_gen_test] Code: Unable to access opcode bytes at 0xffffffff9ffffff2. RSP: 0018:ffffc900015bfeb8 EFLAGS: 00010246 RAX: ffffffffffffffea RBX: ffffffffa0002080 RC...

EPSS: Низкий
github логотип

GHSA-23wh-25r8-cjxj

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13) flushCache, or (14) product parameter. Fixed in Build 11072.

EPSS: Низкий
github логотип

GHSA-23wg-mwgh-c5w5

около 3 лет назад

Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 625, SD 835, SD 845, SD 850, SDA660.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23wf-qmmc-4cr6

больше 3 лет назад

Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-23wf-343v-3cqg

больше 3 лет назад

Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

EPSS: Средний
github логотип

GHSA-23wc-v4mf-x7v4

около 7 лет назад

Directory Traversal in intsol-package

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23wc-j7fg-6xp5

почти 2 года назад

Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a certain period after the attacker has attempted to log in illegally by continuously attempting unauthorized login to the Web server function. The impact of this vulnerability will persist while the attacker continues to attempt unauthorized login.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23w9-x4hx-5jv5

около 3 лет назад

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23w9-jw3m-h5hj

около 3 лет назад

The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

EPSS: Низкий
github логотип

GHSA-23w9-g78h-f93v

около 3 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-23w8-x79h-65g9

4 месяца назад

Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23w8-jvp8-xp5w

около 3 лет назад

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23w8-jcvm-j4jg

больше 3 лет назад

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

EPSS: Низкий
github логотип

GHSA-23w8-fw6w-p2gr

около 3 лет назад

An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23wp-rxm7-f6f3

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-23wp-pqh4-8w8f

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-23wj-wvvj-vgcc

Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23wj-r557-8c5p

tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-23wj-h8fm-chf2

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23wj-fq4f-57vr

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-23wh-q78v-xxm4

In the Linux kernel, the following vulnerability has been resolved: tracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit() When trace_get_event_file() failed, gen_kretprobe_test will be assigned as the error code. If module kprobe_event_gen_test is removed now, the null pointer dereference will happen in kprobe_event_gen_test_exit(). Check if gen_kprobe_test or gen_kretprobe_test is error code or NULL before dereference them. BUG: kernel NULL pointer dereference, address: 0000000000000012 PGD 0 P4D 0 Oops: 0000 [#1] SMP PTI CPU: 3 PID: 2210 Comm: modprobe Not tainted 6.1.0-rc1-00171-g2159299a3b74-dirty #217 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014 RIP: 0010:kprobe_event_gen_test_exit+0x1c/0xb5 [kprobe_event_gen_test] Code: Unable to access opcode bytes at 0xffffffff9ffffff2. RSP: 0018:ffffc900015bfeb8 EFLAGS: 00010246 RAX: ffffffffffffffea RBX: ffffffffa0002080 RC...

0%
Низкий
3 месяца назад
github логотип
GHSA-23wh-25r8-cjxj

Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13) flushCache, or (14) product parameter. Fixed in Build 11072.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23wg-mwgh-c5w5

Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 625, SD 835, SD 845, SD 850, SDA660.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-23wf-qmmc-4cr6

Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-23wf-343v-3cqg

Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

25%
Средний
больше 3 лет назад
github логотип
GHSA-23wc-v4mf-x7v4

Directory Traversal in intsol-package

CVSS3: 7.5
1%
Низкий
около 7 лет назад
github логотип
GHSA-23wc-j7fg-6xp5

Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from logging into the Web server function for a certain period after the attacker has attempted to log in illegally by continuously attempting unauthorized login to the Web server function. The impact of this vulnerability will persist while the attacker continues to attempt unauthorized login.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-23w9-x4hx-5jv5

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

CVSS3: 6.1
6%
Низкий
около 3 лет назад
github логотип
GHSA-23w9-jw3m-h5hj

The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23w9-g78h-f93v

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
10%
Средний
около 3 лет назад
github логотип
GHSA-23w8-x79h-65g9

Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-23w8-jvp8-xp5w

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. The server typically logs activity only when a client application specifies that logging is desired. This can be problematic for use cases in a regulated industry, where server-side logging is required in additional situations.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-23w8-jcvm-j4jg

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-23w8-fw6w-p2gr

An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.

CVSS3: 5.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу