Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3g64-6hgp-5m64

около 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3g64-2wg6-7p8r

почти 2 года назад

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g63-p2hp-v8xg

почти 4 года назад

eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

EPSS: Низкий
github логотип

GHSA-3g63-2rpp-wc2m

около 1 года назад

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g62-vr55-m6hc

около 3 лет назад

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g62-9qpr-j338

больше 3 лет назад

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

EPSS: Низкий
github логотип

GHSA-3g62-98rr-25fp

больше 3 лет назад

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3g5x-2qp3-gm68

больше 1 года назад

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3g5w-ccf9-qgvg

почти 3 года назад

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g5w-6pw7-6hrp

около 3 лет назад

Path Traversal In Eclipse GlassFish

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g5v-m9jm-mw8w

больше 3 лет назад

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g5v-28p4-h3v9

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3g5r-c4ph-rc9c

12 месяцев назад

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3g5r-3c4p-wrgj

больше 3 лет назад

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g5p-5p6j-r9qp

больше 1 года назад

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3g5m-g7r7-6pwf

больше 3 лет назад

get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g5m-332q-27r3

больше 3 лет назад

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g5j-8vj8-rhj3

больше 3 лет назад

Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3g5h-5mpr-m5qx

больше 3 лет назад

SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.

EPSS: Низкий
github логотип

GHSA-3g5g-jqgq-pgf2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g64-6hgp-5m64

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.

CVSS3: 10
0%
Низкий
около 1 года назад
github логотип
GHSA-3g64-2wg6-7p8r

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

CVSS3: 5.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-3g63-p2hp-v8xg

eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3g63-2rpp-wc2m

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3g62-vr55-m6hc

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3g62-9qpr-j338

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g62-98rr-25fp

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

CVSS3: 9.8
34%
Средний
больше 3 лет назад
github логотип
GHSA-3g5x-2qp3-gm68

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
30%
Средний
больше 1 года назад
github логотип
GHSA-3g5w-ccf9-qgvg

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3g5w-6pw7-6hrp

Path Traversal In Eclipse GlassFish

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3g5v-m9jm-mw8w

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5v-28p4-h3v9

In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3g5r-c4ph-rc9c

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.

CVSS3: 4.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3g5r-3c4p-wrgj

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5p-5p6j-r9qp

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g5m-g7r7-6pwf

get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5m-332q-27r3

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5j-8vj8-rhj3

Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5h-5mpr-m5qx

SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5g-jqgq-pgf2

Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу