Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3g3j-w5cc-fqpr

около 1 года назад

A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3g3h-v46v-fqhf

больше 1 года назад

Microsoft SQL Server Elevation of Privilege Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g3h-c682-r9g7

больше 3 лет назад

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is incorrectly validated which may lead to denial of service.

EPSS: Низкий
github логотип

GHSA-3g3h-99q7-v8x2

больше 1 года назад

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g3h-74p9-27c2

больше 3 лет назад

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

EPSS: Низкий
github логотип

GHSA-3g3g-g7r8-6v7p

почти 4 года назад

SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.

EPSS: Низкий
github логотип

GHSA-3g3g-f89f-9wh3

больше 3 лет назад

Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Corporate Lending, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Corporate Lending accessible data as well as unauthorized read access to a subset of Oracle Banking Corporate Lending accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g3g-4368-2m5v

больше 2 лет назад

Microsoft Outlook Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g3f-pff6-g3m3

около 2 лет назад

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3g3f-crm9-qvmw

около 2 лет назад

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g3f-97cc-fc4h

больше 3 лет назад

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3g3c-85xr-23j3

почти 4 года назад

Denial of service in Debian IRC Epic/epic4 client via a long string.

EPSS: Низкий
github логотип

GHSA-3g37-x67f-m9rp

почти 4 года назад

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

EPSS: Низкий
github логотип

GHSA-3g37-ghfj-6c5g

больше 1 года назад

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

CVSS3: 4.6
EPSS: Средний
github логотип

GHSA-3g36-jm7h-4mqf

около 1 года назад

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3g36-gf7c-75qw

10 месяцев назад

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g36-27c8-73r9

почти 2 года назад

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263107. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3g35-v53r-gpxc

почти 2 года назад

Mattermost race condition

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-3g35-2jhp-9xcc

больше 3 лет назад

In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in MagickCore/memory.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g33-qjmm-8mwx

около 2 лет назад

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers to deactivate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g3j-w5cc-fqpr

A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3g3h-v46v-fqhf

Microsoft SQL Server Elevation of Privilege Vulnerability

CVSS3: 8.8
5%
Низкий
больше 1 года назад
github логотип
GHSA-3g3h-c682-r9g7

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is incorrectly validated which may lead to denial of service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g3h-99q7-v8x2

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g3h-74p9-27c2

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g3g-g7r8-6v7p

SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g3g-f89f-9wh3

Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Corporate Lending, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Corporate Lending accessible data as well as unauthorized read access to a subset of Oracle Banking Corporate Lending accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g3g-4368-2m5v

Microsoft Outlook Denial of Service Vulnerability

CVSS3: 7.5
6%
Низкий
больше 2 лет назад
github логотип
GHSA-3g3f-pff6-g3m3

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.

CVSS3: 8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3g3f-crm9-qvmw

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

CVSS3: 8.8
9%
Низкий
около 2 лет назад
github логотип
GHSA-3g3f-97cc-fc4h

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g3c-85xr-23j3

Denial of service in Debian IRC Epic/epic4 client via a long string.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g37-x67f-m9rp

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3g37-ghfj-6c5g

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

CVSS3: 4.6
17%
Средний
больше 1 года назад
github логотип
GHSA-3g36-jm7h-4mqf

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

CVSS3: 7.3
2%
Низкий
около 1 года назад
github логотип
GHSA-3g36-gf7c-75qw

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g36-27c8-73r9

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263107. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3g35-v53r-gpxc

Mattermost race condition

CVSS3: 2.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3g35-2jhp-9xcc

In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in MagickCore/memory.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g33-qjmm-8mwx

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers to deactivate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу