Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3h4r-2q6q-wfr8

больше 1 года назад

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3h4q-7386-ff6m

больше 3 лет назад

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

EPSS: Низкий
github логотип

GHSA-3h4p-v99m-68x5

почти 4 года назад

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3h4p-g442-4q4v

около 1 года назад

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h4m-m55v-gx4m

больше 2 лет назад

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4j-qhvh-q69x

больше 3 лет назад

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4h-w66g-8c4g

почти 4 года назад

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

EPSS: Средний
github логотип

GHSA-3h4h-g6p9-v72m

11 месяцев назад

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4g-vcc2-xxf3

9 месяцев назад

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4g-q9gm-hwvc

больше 3 лет назад

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.

EPSS: Низкий
github логотип

GHSA-3h4g-986f-gvf8

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

EPSS: Низкий
github логотип

GHSA-3h4g-2mjp-7xfp

почти 4 года назад

Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

EPSS: Низкий
github логотип

GHSA-3h4f-jgvh-wjvm

больше 3 лет назад

src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3h4f-76g6-g5wc

больше 3 лет назад

In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive.

EPSS: Низкий
github логотип

GHSA-3h49-gmxg-3c7g

10 месяцев назад

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3h49-76hw-pv6f

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan Carpenter reported a Smack static checker warning: fs/smb/client/cifsfs.c:1981 init_cifs() error: we previously assumed 'serverclose_wq' could be null (see line 1895) The patch which introduced the serverclose workqueue used the wrong oredering in error paths in init_cifs() for freeing it on errors.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h47-86qq-gprm

больше 3 лет назад

Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

EPSS: Низкий
github логотип

GHSA-3h45-h6mj-8qm2

больше 1 года назад

A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3h45-5qrh-cg5g

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

больше 1 года назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h4r-2q6q-wfr8

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h4q-7386-ff6m

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4p-v99m-68x5

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3h4p-g442-4q4v

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3h4m-m55v-gx4m

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3h4j-qhvh-q69x

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4h-w66g-8c4g

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

29%
Средний
почти 4 года назад
github логотип
GHSA-3h4h-g6p9-v72m

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3h4g-vcc2-xxf3

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3h4g-q9gm-hwvc

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4g-986f-gvf8

An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4g-2mjp-7xfp

Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3h4f-jgvh-wjvm

src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4f-76g6-g5wc

In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h49-gmxg-3c7g

An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.

CVSS3: 3.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-3h49-76hw-pv6f

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential null pointer use in destroy_workqueue in init_cifs error path Dan Carpenter reported a Smack static checker warning: fs/smb/client/cifsfs.c:1981 init_cifs() error: we previously assumed 'serverclose_wq' could be null (see line 1895) The patch which introduced the serverclose workqueue used the wrong oredering in error paths in init_cifs() for freeing it on errors.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h47-86qq-gprm

Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3h45-h6mj-8qm2

A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h45-5qrh-cg5g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу