Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3px8-2p4q-xpwm

9 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3px7-w424-22rw

почти 4 года назад

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3px7-qfpp-9fx8

больше 3 лет назад

Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

EPSS: Низкий
github логотип

GHSA-3px7-mx75-562c

больше 3 лет назад

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.

EPSS: Средний
github логотип

GHSA-3px7-jm2p-6h2c

больше 2 лет назад

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3px7-c4j3-576r

8 месяцев назад

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3px7-9cxh-c3q3

около 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3px6-x742-ffjj

больше 3 лет назад

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.

EPSS: Низкий
github логотип

GHSA-3px6-98xq-7ggw

больше 3 лет назад

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3px5-wjh3-9x6r

больше 3 лет назад

Mautic stored Cross-site Scripting (XSS)

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3px5-66w8-x4q8

12 месяцев назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3px5-5wr3-7444

больше 3 лет назад

Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-3px4-cc65-vwjj

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized before the interrupt is registered. If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference. This error condition has been observed during system boot on Rb3Gen2.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3px4-37qg-4m28

больше 1 года назад

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272621 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3px3-34w3-c9jf

почти 4 года назад

PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

EPSS: Низкий
github логотип

GHSA-3pww-qvr8-6mhp

около 2 лет назад

Ray Path Traversal vulnerability

CVSS3: 9.3
EPSS: Высокий
github логотип

GHSA-3pww-q2mq-vwqc

почти 4 года назад

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.

EPSS: Низкий
github логотип

GHSA-3pww-pqg2-m2hm

около 2 лет назад

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3pww-g69g-29xx

почти 4 года назад

Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

EPSS: Средний
github логотип

GHSA-3pwv-p24f-xm44

почти 4 года назад

Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file format. NOTE: some of these details are obtained from third party information.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3px8-2p4q-xpwm

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.

CVSS3: 4.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-3px7-w424-22rw

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3px7-qfpp-9fx8

Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3px7-mx75-562c

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'.

34%
Средний
больше 3 лет назад
github логотип
GHSA-3px7-jm2p-6h2c

encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3px7-c4j3-576r

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

CVSS3: 8.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3px7-9cxh-c3q3

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.

CVSS3: 8.5
1%
Низкий
около 1 года назад
github логотип
GHSA-3px6-x742-ffjj

The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version 4.1.3, from version 4.2.0 before version 4.2.5, from version 4.3.0 before version 4.3.4, and version 4.4.0 allows remote attackers with portal access to view arbitrary issues in Jira Service Desk projects via a path traversal vulnerability. Note that when the 'Anyone can email the service desk or raise a request in the portal' setting is enabled, an attacker can grant themselves portal access, allowing them to exploit the vulnerability.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3px6-98xq-7ggw

An exploitable SQL injection vulnerability exists in the DownloadWindow.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3px5-wjh3-9x6r

Mautic stored Cross-site Scripting (XSS)

CVSS3: 9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3px5-66w8-x4q8

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3px5-5wr3-7444

Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Gateway for Mobile Devices accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Gateway for Mobile Devices accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3px4-cc65-vwjj

In the Linux kernel, the following vulnerability has been resolved: media: venus: protect against spurious interrupts during probe Make sure the interrupt handler is initialized before the interrupt is registered. If the IRQ is registered before hfi_create(), it's possible that an interrupt fires before the handler setup is complete, leading to a NULL dereference. This error condition has been observed during system boot on Rb3Gen2.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3px4-37qg-4m28

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272621 was assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3px3-34w3-c9jf

PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3pww-qvr8-6mhp

Ray Path Traversal vulnerability

CVSS3: 9.3
87%
Высокий
около 2 лет назад
github логотип
GHSA-3pww-q2mq-vwqc

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3pww-pqg2-m2hm

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3pww-g69g-29xx

Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.

38%
Средний
почти 4 года назад
github логотип
GHSA-3pwv-p24f-xm44

Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file format. NOTE: some of these details are obtained from third party information.

17%
Средний
почти 4 года назад

Уязвимостей на страницу