Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mqc-hxx7-9f8m

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

EPSS: Низкий
github логотип

GHSA-3mqc-98m9-f5mm

больше 3 лет назад

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to disclose kernel memory.

EPSS: Низкий
github логотип

GHSA-3mqc-7jv9-w89m

больше 3 лет назад

SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-3mqc-6cqg-j6mm

больше 3 лет назад

Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3mq9-xhgq-r7gj

4 дня назад

EVE: SSH as Root Unlockable Without Triggering Measured Boot

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mq9-vrwc-6hf2

почти 4 года назад

F-Prot Antivirus for Linux x86 Mail Servers 4.6.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

EPSS: Низкий
github логотип

GHSA-3mq9-phgq-f2wv

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.

EPSS: Низкий
github логотип

GHSA-3mq8-695h-7r35

около 1 года назад

The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mq7-vphm-cjch

больше 2 лет назад

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mq7-j5f9-79xq

почти 2 года назад

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mq7-67j8-qhqj

больше 3 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-3mq7-3ggv-qpgc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

EPSS: Низкий
github логотип

GHSA-3mq6-q8x8-h9pp

больше 3 лет назад

Windows Graphics Component Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-3mq5-m58g-fgj3

больше 3 лет назад

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

EPSS: Низкий
github логотип

GHSA-3mq5-fq9h-gj7j

больше 3 лет назад

Duplicate Advisory: Denial of Service due to parser crash

EPSS: Низкий
github логотип

GHSA-3mq5-2hmg-6cr7

больше 2 лет назад

A stack based out-of-bounds write flaw was found in the netfilter subsystem in the Linux kernel. If the expression length is a multiple of 4 (register size), the `nft_exthdr_eval` family of functions writes 4 NULL bytes past the end of the `regs` argument, leading to stack corruption and potential information disclosure or a denial of service.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mq4-x52h-fcwc

больше 3 лет назад

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3mpv-xg32-wjg6

больше 3 лет назад

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

EPSS: Средний
github логотип

GHSA-3mpv-vc7v-xpc6

почти 4 года назад

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-3mpv-gr2q-vh5j

больше 3 лет назад

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mqc-hxx7-9f8m

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mqc-98m9-f5mm

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to disclose kernel memory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mqc-7jv9-w89m

SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mqc-6cqg-j6mm

Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

CVSS3: 4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mq9-xhgq-r7gj

EVE: SSH as Root Unlockable Without Triggering Measured Boot

CVSS3: 5.9
0%
Низкий
4 дня назад
github логотип
GHSA-3mq9-vrwc-6hf2

F-Prot Antivirus for Linux x86 Mail Servers 4.6.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mq9-phgq-f2wv

Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mq8-695h-7r35

The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
около 1 года назад
github логотип
GHSA-3mq7-vphm-cjch

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mq7-j5f9-79xq

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mq7-67j8-qhqj

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mq7-3ggv-qpgc

Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mq6-q8x8-h9pp

Windows Graphics Component Information Disclosure Vulnerability

CVSS3: 5.5
14%
Средний
больше 3 лет назад
github логотип
GHSA-3mq5-m58g-fgj3

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mq5-fq9h-gj7j

Duplicate Advisory: Denial of Service due to parser crash

больше 3 лет назад
github логотип
GHSA-3mq5-2hmg-6cr7

A stack based out-of-bounds write flaw was found in the netfilter subsystem in the Linux kernel. If the expression length is a multiple of 4 (register size), the `nft_exthdr_eval` family of functions writes 4 NULL bytes past the end of the `regs` argument, leading to stack corruption and potential information disclosure or a denial of service.

CVSS3: 6.1
больше 2 лет назад
github логотип
GHSA-3mq4-x52h-fcwc

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVSS3: 7.5
54%
Средний
больше 3 лет назад
github логотип
GHSA-3mpv-xg32-wjg6

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

11%
Средний
больше 3 лет назад
github логотип
GHSA-3mpv-vc7v-xpc6

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3mpv-gr2q-vh5j

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу