Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mph-v6cr-ghhj

7 месяцев назад

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-3mph-2jfm-48f3

больше 3 лет назад

The mintToken function of a smart contract implementation for BitcoinAgileToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mpg-q26j-83j5

около 3 лет назад

Command injection in yiisoft/yii2-gii

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mpf-rq8q-xcv5

больше 3 лет назад

The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mpf-rcc7-5347

почти 2 года назад

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpf-fhf9-62mx

8 месяцев назад

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mpf-9cvv-qh7g

больше 3 лет назад

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.5.0 and below, TIBCO ActiveSpaces - Developer Edition: versions 4.5.0 and below, and TIBCO ActiveSpaces - Enterprise Edition: versions 4.5.0 and below.

EPSS: Низкий
github логотип

GHSA-3mpf-56v2-rjgc

11 дней назад

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3mpc-j5x7-cjc8

почти 4 года назад

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

EPSS: Низкий
github логотип

GHSA-3mpc-949c-h3m6

больше 3 лет назад

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mp9-x5q5-63w3

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3mp9-g29g-6w9m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mp7-wcrh-r295

больше 3 лет назад

libmobi is vulnerable to Use of Out-of-range Pointer Offset

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3mp7-3wf9-mp89

около 2 лет назад

Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mp6-x287-jf43

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3mp6-r5gq-47xq

больше 3 лет назад

Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to read arbitrary files via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mp6-cvg4-cj7v

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System allows Upload a Web Shell to a Web Server.This issue affects Property Lot Management System: from n/a through 4.2.38.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3mp6-8h5j-hwh9

больше 1 года назад

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3mp5-972c-2h7x

почти 4 года назад

Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.

EPSS: Низкий
github логотип

GHSA-3mp5-8f97-395w

почти 4 года назад

ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mph-v6cr-ghhj

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVSS3: 4.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mph-2jfm-48f3

The mintToken function of a smart contract implementation for BitcoinAgileToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpg-q26j-83j5

Command injection in yiisoft/yii2-gii

CVSS3: 8.8
4%
Низкий
около 3 лет назад
github логотип
GHSA-3mpf-rq8q-xcv5

The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpf-rcc7-5347

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3mpf-fhf9-62mx

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3mpf-9cvv-qh7g

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.5.0 and below, TIBCO ActiveSpaces - Developer Edition: versions 4.5.0 and below, and TIBCO ActiveSpaces - Enterprise Edition: versions 4.5.0 and below.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpf-56v2-rjgc

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.

CVSS3: 5.1
0%
Низкий
11 дней назад
github логотип
GHSA-3mpc-j5x7-cjc8

Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3mpc-949c-h3m6

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp9-x5q5-63w3

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp9-g29g-6w9m

Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp7-wcrh-r295

libmobi is vulnerable to Use of Out-of-range Pointer Offset

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp7-3wf9-mp89

Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3mp6-x287-jf43

Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1, and 4.2-beta1; Application Management Suite (AMS) 2.0.0.SR3; and tc Server 6.0.20.B allows remote authenticated users to inject arbitrary web script or HTML via the Description field. NOTE: some of these details are obtained from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mp6-r5gq-47xq

Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to read arbitrary files via unspecified vectors.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3mp6-cvg4-cj7v

Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System allows Upload a Web Shell to a Web Server.This issue affects Property Lot Management System: from n/a through 4.2.38.

CVSS3: 9.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mp6-8h5j-hwh9

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

CVSS3: 8.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3mp5-972c-2h7x

Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mp5-8f97-395w

ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу