Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mmp-v5fp-4vcm

6 месяцев назад

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3mmp-fjhh-4r72

около 4 лет назад

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.

EPSS: Низкий
github логотип

GHSA-3mmp-fgv2-crf2

почти 4 года назад

Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.

EPSS: Низкий
github логотип

GHSA-3mmp-9xr2-4q46

7 месяцев назад

A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mmp-9r95-wfp8

9 месяцев назад

A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3mmm-mj5x-47f4

больше 3 лет назад

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mmm-g63g-fr84

больше 3 лет назад

The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mmm-4r2q-pghm

больше 3 лет назад

Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3mmm-4792-65w2

больше 3 лет назад

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS: Низкий
github логотип

GHSA-3mmj-vfm4-rpfq

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.

EPSS: Низкий
github логотип

GHSA-3mmj-mrr2-5rmx

почти 4 года назад

Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.

EPSS: Низкий
github логотип

GHSA-3mmj-45hw-28gw

больше 3 лет назад

Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 through 4.0.8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest Additions for Windows.

EPSS: Низкий
github логотип

GHSA-3mmh-vq9w-4c3g

около 3 лет назад

Microweber vulnerable to Reflected Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mmh-h28h-wgxq

больше 3 лет назад

The “WooLentor – WooCommerce Elementor Addons + Builder� WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

EPSS: Низкий
github логотип

GHSA-3mmg-7c2q-8938

2 дня назад

`sha-rust` was removed from crates.io for malicious code

EPSS: Низкий
github логотип

GHSA-3mmf-7v44-cphp

больше 3 лет назад

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.

EPSS: Низкий
github логотип

GHSA-3mmf-6wp6-5hfj

почти 3 года назад

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mmf-29wp-jc9p

около 1 года назад

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3mmc-w8vq-jvw8

почти 4 года назад

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

EPSS: Низкий
github логотип

GHSA-3mm9-2p44-rw39

больше 1 года назад

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mmp-v5fp-4vcm

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.

CVSS3: 3.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mmp-fjhh-4r72

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3mmp-fgv2-crf2

Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mmp-9xr2-4q46

A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mmp-9r95-wfp8

A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3mmm-mj5x-47f4

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmm-g63g-fr84

The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmm-4r2q-pghm

Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmm-4792-65w2

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmj-vfm4-rpfq

Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3mmj-mrr2-5rmx

Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mmj-45hw-28gw

Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 through 4.0.8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest Additions for Windows.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmh-vq9w-4c3g

Microweber vulnerable to Reflected Cross-site Scripting

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3mmh-h28h-wgxq

The “WooLentor – WooCommerce Elementor Addons + Builder� WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmg-7c2q-8938

`sha-rust` was removed from crates.io for malicious code

2 дня назад
github логотип
GHSA-3mmf-7v44-cphp

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mmf-6wp6-5hfj

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3mmf-29wp-jc9p

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

CVSS3: 4.6
0%
Низкий
около 1 года назад
github логотип
GHSA-3mmc-w8vq-jvw8

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mm9-2p44-rw39

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
больше 1 года назад

Уязвимостей на страницу