Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 436

Количество 289 436

github логотип

GHSA-226h-h99r-j24r

больше 1 года назад

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-226h-772w-v9vj

около 3 лет назад

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

EPSS: Низкий
github логотип

GHSA-226h-2qfh-4hf8

12 месяцев назад

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-226c-wpq4-r9cj

больше 3 лет назад

SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

EPSS: Низкий
github логотип

GHSA-2269-968q-6hcq

больше 2 лет назад

Memory corruption due to improper access control in Qualcomm IPC.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2268-w43v-j544

около 1 года назад

Cross-Site Request Forgery (CSRF) in stitionai/devika

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2268-rqjm-gx38

почти 2 года назад

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2268-hc24-w7pm

больше 2 лет назад

Azure Network Watcher Agent Security Feature Bypass Vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2268-98wh-qfhf

больше 1 года назад

JLine vulnerable to out of memory error

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2268-76c3-x85m

больше 3 лет назад

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2267-x99j-hcv3

6 месяцев назад

Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2267-87gq-vw4p

больше 2 лет назад

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2267-86vq-8f86

больше 3 лет назад

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2266-6m7r-fxww

около 3 лет назад

Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1.

EPSS: Низкий
github логотип

GHSA-2264-q7fx-w4x7

больше 3 лет назад

Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.

EPSS: Средний
github логотип

GHSA-2264-54r3-3rjm

больше 3 лет назад

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

EPSS: Средний
github логотип

GHSA-2263-jwgm-wv97

больше 3 лет назад

Showdoc XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2263-gvv9-23vp

больше 3 лет назад

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

EPSS: Низкий
github логотип

GHSA-2263-7263-q848

больше 3 лет назад

The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0846.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2262-c75j-5hr5

почти 2 года назад

Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-226h-h99r-j24r

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-226h-772w-v9vj

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

3%
Низкий
около 3 лет назад
github логотип
GHSA-226h-2qfh-4hf8

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-226c-wpq4-r9cj

SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2269-968q-6hcq

Memory corruption due to improper access control in Qualcomm IPC.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2268-w43v-j544

Cross-Site Request Forgery (CSRF) in stitionai/devika

CVSS3: 8.8
около 1 года назад
github логотип
GHSA-2268-rqjm-gx38

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

CVSS3: 5.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2268-hc24-w7pm

Azure Network Watcher Agent Security Feature Bypass Vulnerability.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2268-98wh-qfhf

JLine vulnerable to out of memory error

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2268-76c3-x85m

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2267-x99j-hcv3

Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2267-87gq-vw4p

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2267-86vq-8f86

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2266-6m7r-fxww

Improper Privilege Management in GitHub repository openemr/openemr prior to 7.0.0.1.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2264-q7fx-w4x7

Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.

64%
Средний
больше 3 лет назад
github логотип
GHSA-2264-54r3-3rjm

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

33%
Средний
больше 3 лет назад
github логотип
GHSA-2263-jwgm-wv97

Showdoc XSS Vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2263-gvv9-23vp

The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2263-7263-q848

The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0846.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2262-c75j-5hr5

Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.

CVSS3: 8.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу