Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3m98-m7jj-v78v

около 1 года назад

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Running a mount command may unexpectedly execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m98-cmhq-pc7h

2 дня назад

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify database information.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3m96-w3xc-w9j4

почти 4 года назад

The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m95-wfxh-25xv

10 месяцев назад

Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cryptocurrency Widgets Pack: from n/a through 2.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3m95-7rcm-xpxr

больше 3 лет назад

Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to execute arbitrary SQL commands via vectors related to the (1) search or (2) list functionality.

EPSS: Низкий
github логотип

GHSA-3m93-m4q6-mc6v

почти 6 лет назад

Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3m93-8pm8-gqxj

больше 3 лет назад

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

EPSS: Средний
github логотип

GHSA-3m93-68mf-mv6r

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3m8x-jjr4-6gqq

больше 3 лет назад

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

EPSS: Низкий
github логотип

GHSA-3m8x-7qxf-c378

больше 3 лет назад

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3m8w-h8mm-xqvp

3 месяца назад

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8w-442m-3p2q

больше 3 лет назад

Jenkins Artifactory Plugin missing permission check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8w-2mvj-9q7j

около 1 года назад

Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m8v-mqfw-xp3g

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: PCI: s390: Fix use-after-free of PCI resources with per-function hotplug On s390 PCI functions may be hotplugged individually even when they belong to a multi-function device. In particular on an SR-IOV device VFs may be removed and later re-added. In commit a50297cf8235 ("s390/pci: separate zbus creation from scanning") it was missed however that struct pci_bus and struct zpci_bus's resource list retained a reference to the PCI functions MMIO resources even though those resources are released and freed on hot-unplug. These stale resources may subsequently be claimed when the PCI function re-appears resulting in use-after-free. One idea of fixing this use-after-free in s390 specific code that was investigated was to simply keep resources around from the moment a PCI function first appeared until the whole virtual PCI bus created for a multi-function device disappears. The problem with this however is that due to...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m8v-9pw4-4fx9

больше 3 лет назад

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-3m8r-w7xg-jqvw

3 месяца назад

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVSS3: 10
EPSS: Средний
github логотип

GHSA-3m8r-4f2m-v89p

больше 2 лет назад

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3m8q-vjx5-jjcc

почти 3 года назад

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ALPS07628587.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3m8q-g6w4-24q3

больше 3 лет назад

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3m8p-xpm6-8ww3

больше 3 лет назад

Ansible Arbitrary Code Execution

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m98-m7jj-v78v

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Running a mount command may unexpectedly execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3m98-cmhq-pc7h

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify database information.

CVSS3: 7.1
0%
Низкий
2 дня назад
github логотип
GHSA-3m96-w3xc-w9j4

The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3m95-wfxh-25xv

Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cryptocurrency Widgets Pack: from n/a through 2.0.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3m95-7rcm-xpxr

Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to execute arbitrary SQL commands via vectors related to the (1) search or (2) list functionality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m93-m4q6-mc6v

Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in Ansible

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
github логотип
GHSA-3m93-8pm8-gqxj

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

53%
Средний
больше 3 лет назад
github логотип
GHSA-3m93-68mf-mv6r

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8x-jjr4-6gqq

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8x-7qxf-c378

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8w-h8mm-xqvp

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3m8w-442m-3p2q

Jenkins Artifactory Plugin missing permission check

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8w-2mvj-9q7j

Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3m8v-mqfw-xp3g

In the Linux kernel, the following vulnerability has been resolved: PCI: s390: Fix use-after-free of PCI resources with per-function hotplug On s390 PCI functions may be hotplugged individually even when they belong to a multi-function device. In particular on an SR-IOV device VFs may be removed and later re-added. In commit a50297cf8235 ("s390/pci: separate zbus creation from scanning") it was missed however that struct pci_bus and struct zpci_bus's resource list retained a reference to the PCI functions MMIO resources even though those resources are released and freed on hot-unplug. These stale resources may subsequently be claimed when the PCI function re-appears resulting in use-after-free. One idea of fixing this use-after-free in s390 specific code that was investigated was to simply keep resources around from the moment a PCI function first appeared until the whole virtual PCI bus created for a multi-function device disappears. The problem with this however is that due to...

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3m8v-9pw4-4fx9

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

CVSS3: 10
10%
Средний
больше 3 лет назад
github логотип
GHSA-3m8r-w7xg-jqvw

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVSS3: 10
38%
Средний
3 месяца назад
github логотип
GHSA-3m8r-4f2m-v89p

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3m8q-vjx5-jjcc

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ALPS07628587.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3m8q-g6w4-24q3

Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621...

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m8p-xpm6-8ww3

Ansible Arbitrary Code Execution

CVSS3: 8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу