Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3c3x-89f2-9xg4

больше 2 лет назад

A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file appointmentapproval.php. The manipulation of the argument time leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236211.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3c3v-8gm2-qxwq

почти 4 года назад

Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.

EPSS: Средний
github логотип

GHSA-3c3v-6qp8-v5gc

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n/a through 3.25.10.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c3r-w27c-3p75

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during a deinitialization path.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c3r-rm96-x7cw

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921s: fix a possible memory leak in mt7921_load_patch Always release fw data at the end of mt7921_load_patch routine.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c3r-frp2-2rrp

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9736.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c3r-82gp-wc94

больше 3 лет назад

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3c3r-6mf2-xcmp

около 2 лет назад

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c3q-vw42-rfc2

больше 1 года назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3c3p-xh4f-pfh7

5 месяцев назад

json-schema-editor-visual vulnerable to prototype pollution

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c3m-qp4j-mgv8

больше 3 лет назад

An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process() located in sample_generator.cpp. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-3c3m-ffrh-rq6p

больше 3 лет назад

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

EPSS: Критический
github логотип

GHSA-3c3h-v674-rhqr

больше 3 лет назад

md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c3g-q64x-8mfv

больше 1 года назад

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3c3f-mfjj-vmx7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c3f-93qj-h99f

почти 4 года назад

Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-3c3f-2h7p-qwc8

больше 3 лет назад

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

EPSS: Низкий
github логотип

GHSA-3c3c-wv2g-35jm

почти 4 года назад

Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

EPSS: Низкий
github логотип

GHSA-3c3c-2xp4-j4qp

больше 3 лет назад

The wp-slimstat plugin before 4.8.1 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c39-x2h8-rmf7

больше 3 лет назад

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c3x-89f2-9xg4

A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file appointmentapproval.php. The manipulation of the argument time leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236211.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c3v-8gm2-qxwq

Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.

30%
Средний
почти 4 года назад
github логотип
GHSA-3c3v-6qp8-v5gc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n/a through 3.25.10.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3c3r-w27c-3p75

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during a deinitialization path.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3r-rm96-x7cw

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921s: fix a possible memory leak in mt7921_load_patch Always release fw data at the end of mt7921_load_patch routine.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3c3r-frp2-2rrp

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_list_accounts.php. When parsing the username parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9736.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3r-82gp-wc94

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

CVSS3: 8.1
94%
Критический
больше 3 лет назад
github логотип
GHSA-3c3r-6mf2-xcmp

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3c3q-vw42-rfc2

Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.

CVSS3: 8.8
32%
Средний
больше 1 года назад
github логотип
GHSA-3c3p-xh4f-pfh7

json-schema-editor-visual vulnerable to prototype pollution

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3c3m-qp4j-mgv8

An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process() located in sample_generator.cpp. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3m-ffrh-rq6p

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

94%
Критический
больше 3 лет назад
github логотип
GHSA-3c3h-v674-rhqr

md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3g-q64x-8mfv

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3c3f-mfjj-vmx7

Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3f-93qj-h99f

Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3c3f-2h7p-qwc8

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3c-wv2g-35jm

Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3c3c-2xp4-j4qp

The wp-slimstat plugin before 4.8.1 for WordPress has XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c39-x2h8-rmf7

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу