Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 436

Количество 289 436

github логотип

GHSA-25h3-mw3p-w8r7

около 3 лет назад

Dolibarr CRM allows Privilege Escalation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25h2-xj4x-29h3

почти 3 года назад

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25gx-qr96-f826

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25gw-crq8-3qhc

около 3 лет назад

An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25gw-4pcc-45cf

больше 3 лет назад

Deserialization of Untrusted Data in Apache Batik

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25gv-wg6f-6frp

почти 3 года назад

Centreon SQL Injection vulnerability via esc_name parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gv-mvm7-5h3h

больше 2 лет назад

Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25gv-jrjg-43pj

около 1 месяца назад

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-25gv-fvh4-vpcx

около 3 лет назад

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

EPSS: Низкий
github логотип

GHSA-25gv-85m9-qg67

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25gv-4h88-97v2

7 месяцев назад

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25gr-ph8w-33hc

больше 3 лет назад

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25gr-fx9v-whc8

больше 3 лет назад

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gq-jvx2-vg9x

около 1 года назад

Silverstripe X-Forwarded-Host request hostname injection

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-25gq-3qmx-682c

около 3 лет назад

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gp-h9jh-j64g

больше 3 лет назад

Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

EPSS: Низкий
github логотип

GHSA-25gm-jxwr-cv79

12 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-25gm-f4jj-c4jm

больше 3 лет назад

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25gm-5rg6-r2ph

больше 3 лет назад

pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

EPSS: Низкий
github логотип

GHSA-25gj-gvw5-5xcq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25h3-mw3p-w8r7

Dolibarr CRM allows Privilege Escalation

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-25h2-xj4x-29h3

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-25gx-qr96-f826

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-25gw-crq8-3qhc

An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-25gw-4pcc-45cf

Deserialization of Untrusted Data in Apache Batik

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gv-wg6f-6frp

Centreon SQL Injection vulnerability via esc_name parameter

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-25gv-mvm7-5h3h

Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25gv-jrjg-43pj

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-25gv-fvh4-vpcx

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

1%
Низкий
около 3 лет назад
github логотип
GHSA-25gv-85m9-qg67

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-25gv-4h88-97v2

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-25gr-ph8w-33hc

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gr-fx9v-whc8

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gq-jvx2-vg9x

Silverstripe X-Forwarded-Host request hostname injection

CVSS3: 7.2
около 1 года назад
github логотип
GHSA-25gq-3qmx-682c

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-25gp-h9jh-j64g

Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gm-jxwr-cv79

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.

CVSS3: 7.6
0%
Низкий
12 месяцев назад
github логотип
GHSA-25gm-f4jj-c4jm

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gm-5rg6-r2ph

pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gj-gvw5-5xcq

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу