Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 031

Количество 289 031

github логотип

GHSA-22f3-2777-6wj4

больше 2 лет назад

Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22f2-v57c-j9cx

больше 1 года назад

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22f2-7248-9pxp

больше 1 года назад

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cx-g984-4v34

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."

EPSS: Средний
github логотип

GHSA-22cw-mq2h-w9m7

больше 3 лет назад

A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22cw-hj59-vjwv

11 месяцев назад

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-22cw-c67j-89mh

около 3 лет назад

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22cw-2v9q-5w3r

около 3 лет назад

The Questoes OAB (aka com.pedefeijao.questoesoab) application oab_android_1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22cv-p6m9-w66j

почти 3 года назад

There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22cv-mr79-8p5c

11 месяцев назад

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view HTTP proxy server admin credentials in clear text that are configured on Nexus Dashboard to reach an external network. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-22cr-447g-57w6

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Tahir Ali Jan Bulk YouTube Post Creator allows Reflected XSS. This issue affects Bulk YouTube Post Creator: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22cq-xxr9-jrrv

больше 3 лет назад

Zenario CMS vulnerable to CSRF

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22cq-qqmm-44qr

5 месяцев назад

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-22cq-h96p-qcc2

больше 2 лет назад

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22cq-cq7f-8jm3

около 3 лет назад

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22cp-w34c-5qxr

почти 3 года назад

The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) through 2022-06-27 performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-22cp-6jm2-7pjh

больше 3 лет назад

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

EPSS: Низкий
github логотип

GHSA-22cm-3qf2-2wc7

больше 4 лет назад

LDAP Injection in is-user-valid

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22cf-8wqp-mvp7

больше 3 лет назад

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

EPSS: Низкий
github логотип

GHSA-22cf-67wm-xj29

5 месяцев назад

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22f3-2777-6wj4

Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22f2-v57c-j9cx

Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-22f2-7248-9pxp

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-22cx-g984-4v34

Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."

48%
Средний
больше 3 лет назад
github логотип
GHSA-22cw-mq2h-w9m7

A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22cw-hj59-vjwv

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVSS3: 6.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-22cw-c67j-89mh

Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-22cw-2v9q-5w3r

The Questoes OAB (aka com.pedefeijao.questoesoab) application oab_android_1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22cv-p6m9-w66j

There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221899

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-22cv-mr79-8p5c

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view HTTP proxy server admin credentials in clear text that are configured on Nexus Dashboard to reach an external network. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-22cr-447g-57w6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Tahir Ali Jan Bulk YouTube Post Creator allows Reflected XSS. This issue affects Bulk YouTube Post Creator: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22cq-xxr9-jrrv

Zenario CMS vulnerable to CSRF

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22cq-qqmm-44qr

A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-22cq-h96p-qcc2

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22cq-cq7f-8jm3

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-22cp-w34c-5qxr

The login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) through 2022-06-27 performs expensive RSA key-generation operations, which allows attackers to cause a denial of service (DoS) by requesting that form repeatedly.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-22cp-6jm2-7pjh

Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-22cm-3qf2-2wc7

LDAP Injection in is-user-valid

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-22cf-8wqp-mvp7

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22cf-67wm-xj29

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу