Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fm3-mfvv-cwx4

больше 3 лет назад

Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3fm3-m23v-5r46

около 3 лет назад

Tendermint Client package vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fm2-xfq7-7778

26 дней назад

HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3fm2-hx3h-xm4v

2 месяца назад

Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3fjx-v9x2-fjp6

больше 3 лет назад

Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fjx-g9c9-m3qf

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: No support of struct argument in trampoline programs The current implementation does not support struct argument. This causes a oops when running bpf selftest: $ ./test_progs -a tracing_struct Oops[#1]: CPU -1 Unable to handle kernel paging request at virtual address 0000000000000018, era == 9000000085bef268, ra == 90000000844f3938 rcu: INFO: rcu_preempt detected stalls on CPUs/tasks: rcu: 1-...0: (19 ticks this GP) idle=1094/1/0x4000000000000000 softirq=1380/1382 fqs=801 rcu: (detected by 0, t=5252 jiffies, g=1197, q=52 ncpus=4) Sending NMI from CPU 0 to CPUs 1: rcu: rcu_preempt kthread starved for 2495 jiffies! g1197 f0x0 RCU_GP_DOING_FQS(6) ->state=0x0 ->cpu=2 rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior. rcu: RCU grace-period kthread stack dump: task:rcu_preempt state:I stack:0 pid:15 tgid:15 ppid:2 ...

EPSS: Низкий
github логотип

GHSA-3fjx-35vx-pq97

больше 3 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3fjw-qgvr-6mvc

8 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator allows Retrieve Embedded Sensitive Data. This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through 2.6.8.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3fjw-qcx6-3qqp

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.

EPSS: Низкий
github логотип

GHSA-3fjw-3ffh-wrxh

больше 3 лет назад

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fjv-whfc-w3gr

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3fjv-8r82-6xm9

больше 2 лет назад

Jenkins Fortify Plugin cross-site request forgery vulnerability

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3fjr-pmvp-g6q5

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.

EPSS: Низкий
github логотип

GHSA-3fjr-mgxw-wcwm

больше 3 лет назад

Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fjr-j3qm-96cp

больше 2 лет назад

The JQuery Accordion Menu Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3fjr-h35g-vfc9

11 месяцев назад

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/or write new data. To gain authenticated sessions of other users, the attacker must invest considerable time and effort. This vulnerability has a high impact on the confidentiality and integrity of the application with no effect on the availability of the application.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3fjr-cx6c-863c

3 месяца назад

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3fjq-mm23-rr9w

около 2 месяцев назад

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3fjq-93xj-3f3f

около 6 лет назад

Cross-Site Scripting in serialize-to-js

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3fjm-f94p-cw3r

почти 4 года назад

Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fm3-mfvv-cwx4

Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fm3-m23v-5r46

Tendermint Client package vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3fm2-xfq7-7778

HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover

CVSS3: 8
0%
Низкий
26 дней назад
github логотип
GHSA-3fm2-hx3h-xm4v

Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3fjx-v9x2-fjp6

Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjx-g9c9-m3qf

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: No support of struct argument in trampoline programs The current implementation does not support struct argument. This causes a oops when running bpf selftest: $ ./test_progs -a tracing_struct Oops[#1]: CPU -1 Unable to handle kernel paging request at virtual address 0000000000000018, era == 9000000085bef268, ra == 90000000844f3938 rcu: INFO: rcu_preempt detected stalls on CPUs/tasks: rcu: 1-...0: (19 ticks this GP) idle=1094/1/0x4000000000000000 softirq=1380/1382 fqs=801 rcu: (detected by 0, t=5252 jiffies, g=1197, q=52 ncpus=4) Sending NMI from CPU 0 to CPUs 1: rcu: rcu_preempt kthread starved for 2495 jiffies! g1197 f0x0 RCU_GP_DOING_FQS(6) ->state=0x0 ->cpu=2 rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior. rcu: RCU grace-period kthread stack dump: task:rcu_preempt state:I stack:0 pid:15 tgid:15 ppid:2 ...

0%
Низкий
3 месяца назад
github логотип
GHSA-3fjx-35vx-pq97

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjw-qgvr-6mvc

Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator allows Retrieve Embedded Sensitive Data. This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through 2.6.8.2.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3fjw-qcx6-3qqp

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjw-3ffh-wrxh

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjv-whfc-w3gr

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjv-8r82-6xm9

Jenkins Fortify Plugin cross-site request forgery vulnerability

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3fjr-pmvp-g6q5

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.

0%
Низкий
2 месяца назад
github логотип
GHSA-3fjr-mgxw-wcwm

Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjr-j3qm-96cp

The JQuery Accordion Menu Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcwp-jquery-accordion' shortcode in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3fjr-h35g-vfc9

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/or write new data. To gain authenticated sessions of other users, the attacker must invest considerable time and effort. This vulnerability has a high impact on the confidentiality and integrity of the application with no effect on the availability of the application.

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3fjr-cx6c-863c

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3fjq-mm23-rr9w

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3fjq-93xj-3f3f

Cross-Site Scripting in serialize-to-js

CVSS3: 3.1
0%
Низкий
около 6 лет назад
github логотип
GHSA-3fjm-f94p-cw3r

Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

51%
Средний
почти 4 года назад

Уязвимостей на страницу