Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 031

Количество 289 031

github логотип

GHSA-254v-xjfq-x8gj

больше 3 лет назад

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

EPSS: Низкий
github логотип

GHSA-254v-c952-g64w

6 месяцев назад

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254v-3mjq-6mjm

больше 3 лет назад

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

EPSS: Низкий
github логотип

GHSA-254r-xffm-9c3g

5 месяцев назад

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-254r-9226-v29v

около 3 лет назад

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254q-rqmw-vx45

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in librenms

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-254q-rp36-v2m8

больше 3 лет назад

Missing XML Validation in Apache CXF

EPSS: Средний
github логотип

GHSA-254q-r25r-fwm9

около 3 лет назад

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-254p-hhvc-rr9q

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-254p-9j5r-3fvc

около 3 лет назад

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

EPSS: Низкий
github логотип

GHSA-254m-79rf-mxh7

около 3 лет назад

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

EPSS: Низкий
github логотип

GHSA-254m-3cq9-8624

больше 3 лет назад

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-254j-mmc5-qhpx

около 3 лет назад

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-254j-3m2w-23xr

больше 3 лет назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

EPSS: Низкий
github логотип

GHSA-254h-gvgq-x2xg

11 месяцев назад

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-254g-h6q6-4fxv

больше 3 лет назад

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

EPSS: Низкий
github логотип

GHSA-254f-jwvx-j47x

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

EPSS: Низкий
github логотип

GHSA-254f-c2wq-r664

около 3 лет назад

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

EPSS: Низкий
github логотип

GHSA-254c-893v-cfqr

около 1 месяца назад

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-254c-2j77-4hhm

около 3 лет назад

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-254v-xjfq-x8gj

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-254v-c952-g64w

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-254v-3mjq-6mjm

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-254r-xffm-9c3g

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-254r-9226-v29v

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
6%
Низкий
около 3 лет назад
github логотип
GHSA-254q-rqmw-vx45

Exposure of Sensitive Information to an Unauthorized Actor in librenms

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-254q-rp36-v2m8

Missing XML Validation in Apache CXF

20%
Средний
больше 3 лет назад
github логотип
GHSA-254q-r25r-fwm9

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-254p-hhvc-rr9q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-254p-9j5r-3fvc

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

6%
Низкий
около 3 лет назад
github логотип
GHSA-254m-79rf-mxh7

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

0%
Низкий
около 3 лет назад
github логотип
GHSA-254m-3cq9-8624

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-254j-mmc5-qhpx

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-254j-3m2w-23xr

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-254h-gvgq-x2xg

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-254g-h6q6-4fxv

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-254f-jwvx-j47x

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

4%
Низкий
около 3 лет назад
github логотип
GHSA-254f-c2wq-r664

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

0%
Низкий
около 3 лет назад
github логотип
GHSA-254c-893v-cfqr

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-254c-2j77-4hhm

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу