Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3q76-8594-629m

почти 4 года назад

** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer."

EPSS: Низкий
github логотип

GHSA-3q75-rp5f-jff5

7 месяцев назад

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3q75-gmh9-x7r6

больше 3 лет назад

IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3q75-2gg2-99h4

больше 3 лет назад

The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.

EPSS: Низкий
github логотип

GHSA-3q74-vrwv-v9x3

около 1 года назад

Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3q74-6f83-38mg

больше 3 лет назад

IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3q72-ch8q-5j47

больше 3 лет назад

NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.

EPSS: Низкий
github логотип

GHSA-3q6x-mjrg-68xw

2 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q6x-j6f7-rvxv

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q6x-gxwh-88p9

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3q6w-vp42-26vx

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q6v-mwhw-45h2

около 1 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3q6v-jv77-fpxc

почти 4 года назад

KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

EPSS: Низкий
github логотип

GHSA-3q6v-gv39-h4r6

больше 3 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3q6r-ghxh-24g9

около 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q6q-xxfm-fxqr

почти 4 года назад

Buffer overflow in AIX xdat gives root access to local users.

EPSS: Низкий
github логотип

GHSA-3q6q-qc68-x6pf

больше 3 лет назад

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3q6q-m779-9qvh

почти 4 года назад

The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

EPSS: Низкий
github логотип

GHSA-3q6q-gxwr-7gqv

около 2 месяцев назад

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q6p-xqh5-xhx5

больше 3 лет назад

Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q76-8594-629m

** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer."

7%
Низкий
почти 4 года назад
github логотип
GHSA-3q75-rp5f-jff5

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

CVSS3: 5.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3q75-gmh9-x7r6

IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q75-2gg2-99h4

The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q74-vrwv-v9x3

Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3q74-6f83-38mg

IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.

CVSS3: 4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q72-ch8q-5j47

NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-3q6x-mjrg-68xw

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-3q6x-j6f7-rvxv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3q6x-gxwh-88p9

In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q6w-vp42-26vx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-3q6v-mwhw-45h2

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-3q6v-jv77-fpxc

KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3q6v-gv39-h4r6

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q6r-ghxh-24g9

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3q6q-xxfm-fxqr

Buffer overflow in AIX xdat gives root access to local users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3q6q-qc68-x6pf

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

CVSS3: 9.8
13%
Средний
больше 3 лет назад
github логотип
GHSA-3q6q-m779-9qvh

The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3q6q-gxwr-7gqv

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3q6p-xqh5-xhx5

Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу