Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hxp-x9v3-rrq4

больше 3 лет назад

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.

EPSS: Низкий
github логотип

GHSA-3hxp-v5gh-hxgj

больше 3 лет назад

3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.

EPSS: Низкий
github логотип

GHSA-3hxp-qjj8-fm85

13 дней назад

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3hxp-29c8-25h6

почти 4 года назад

An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hxm-xw7j-7rgj

почти 4 года назад

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3hxh-mh53-wv9q

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imbasynergy ImbaChat allows DOM-Based XSS.This issue affects ImbaChat: from n/a through 3.1.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hxh-g2hm-fh38

6 месяцев назад

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3hxh-8cp2-g4hg

больше 4 лет назад

Use after free and segfault in shape inference functions

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3hxh-7jxm-59x4

больше 3 лет назад

AtomicBucket<T> unconditionally implements Send/Sync

EPSS: Низкий
github логотип

GHSA-3hxg-qg6f-x2wp

почти 4 года назад

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hxg-fxwm-8gf7

больше 1 года назад

CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hxf-p384-rmc6

больше 2 лет назад

A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerability by sending a malicious file inside a crafted zip-compressed file to an affected device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3hxf-g9w5-rj6x

около 1 месяца назад

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3hxc-wcg4-238w

около 1 года назад

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3hx9-v2p4-8c3r

больше 3 лет назад

A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-3hx9-jrq9-5mh9

больше 3 лет назад

TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is provided to ImageMagick. The patch uses a StringInfo type instead of a raw C string to remedy this. This could cause an impact to availability of the application. This flaw affects ImageMagick versions prior to 7.0.9-0.

EPSS: Низкий
github логотип

GHSA-3hx9-99w5-pvxh

почти 3 года назад

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hx8-v7h4-vj64

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox allows PHP Local File Inclusion. This issue affects CSS & JavaScript Toolbox: from n/a through n/a.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hx8-rcv2-389f

около 2 лет назад

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hx8-qgvh-chjg

больше 3 лет назад

In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hxp-x9v3-rrq4

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hxp-v5gh-hxgj

3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hxp-qjj8-fm85

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

CVSS3: 9.9
0%
Низкий
13 дней назад
github логотип
GHSA-3hxp-29c8-25h6

An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by private/index.jsp?partners/ShowNonLocalPartners.do?localID= or private/index.jsp or private/index.jsp?database/databaseTab.jsp or private/index.jsp?activation/activationMainTab.jsp or private/index.jsp?communication/serverTab.jsp or private/index.jsp?emailNotification/notificationTab.jsp.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3hxm-xw7j-7rgj

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

CVSS3: 9.8
81%
Высокий
почти 4 года назад
github логотип
GHSA-3hxh-mh53-wv9q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imbasynergy ImbaChat allows DOM-Based XSS.This issue affects ImbaChat: from n/a through 3.1.4.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3hxh-g2hm-fh38

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hxh-8cp2-g4hg

Use after free and segfault in shape inference functions

CVSS3: 6.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hxh-7jxm-59x4

AtomicBucket<T> unconditionally implements Send/Sync

больше 3 лет назад
github логотип
GHSA-3hxg-qg6f-x2wp

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3hxg-fxwm-8gf7

CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hxf-p384-rmc6

A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerability by sending a malicious file inside a crafted zip-compressed file to an affected device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.

CVSS3: 5.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hxf-g9w5-rj6x

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.

CVSS3: 6.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hxc-wcg4-238w

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3hx9-v2p4-8c3r

A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.

CVSS3: 4.3
11%
Средний
больше 3 лет назад
github логотип
GHSA-3hx9-jrq9-5mh9

TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is provided to ImageMagick. The patch uses a StringInfo type instead of a raw C string to remedy this. This could cause an impact to availability of the application. This flaw affects ImageMagick versions prior to 7.0.9-0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx9-99w5-pvxh

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3hx8-v7h4-vj64

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox allows PHP Local File Inclusion. This issue affects CSS & JavaScript Toolbox: from n/a through n/a.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hx8-rcv2-389f

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3hx8-qgvh-chjg

In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу