Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3pgw-hvj7-xwg9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

EPSS: Низкий
github логотип

GHSA-3pgv-pw29-xppm

больше 3 лет назад

Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pgv-hwxj-pq2c

почти 4 года назад

Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

EPSS: Средний
github логотип

GHSA-3pgp-22cc-4c6r

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3pgm-m73m-qrj2

около 1 года назад

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pgm-jg3q-f445

7 месяцев назад

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

EPSS: Низкий
github логотип

GHSA-3pgm-8wwj-gjwc

почти 3 года назад

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3pgm-5jc2-x2rx

больше 3 лет назад

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pgj-pg6c-r5p7

больше 3 лет назад

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3pgj-h3jv-hj48

около 2 месяцев назад

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pgh-mfvh-3jch

больше 3 лет назад

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pgh-gc83-p85w

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3pgh-f8f3-268r

больше 3 лет назад

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3pgg-hvfr-3phx

больше 3 лет назад

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pgg-fxm7-xv3p

больше 1 года назад

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3pgg-7mmh-564c

больше 3 лет назад

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

EPSS: Низкий
github логотип

GHSA-3pgc-7jf3-5x5g

больше 3 лет назад

Magento 2 Community Edition IDOR Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3pg9-qqg9-8485

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

EPSS: Низкий
github логотип

GHSA-3pg9-mr9f-v7qm

больше 3 лет назад

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3pg9-h6fh-rxcr

больше 3 лет назад

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pgw-hvj7-xwg9

Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgv-pw29-xppm

Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgv-hwxj-pq2c

Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

14%
Средний
почти 4 года назад
github логотип
GHSA-3pgp-22cc-4c6r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.

CVSS3: 9.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3pgm-m73m-qrj2

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3pgm-jg3q-f445

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

0%
Низкий
7 месяцев назад
github логотип
GHSA-3pgm-8wwj-gjwc

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3pgm-5jc2-x2rx

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgj-pg6c-r5p7

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

CVSS3: 5.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgj-h3jv-hj48

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3pgh-mfvh-3jch

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgh-gc83-p85w

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
21%
Средний
больше 3 лет назад
github логотип
GHSA-3pgh-f8f3-268r

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgg-hvfr-3phx

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgg-fxm7-xv3p

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 9
1%
Низкий
больше 1 года назад
github логотип
GHSA-3pgg-7mmh-564c

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgc-7jf3-5x5g

Magento 2 Community Edition IDOR Vulnerability

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pg9-qqg9-8485

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3pg9-mr9f-v7qm

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pg9-h6fh-rxcr

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу