Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-396g-cm65-2gh9

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-396g-3mmq-29wc

почти 2 года назад

D-Link DIR-3040 prog.cgi SetIPv6PppoeSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21651.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-396f-r23h-8cqv

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Johan Ström Background Control allows Path Traversal.This issue affects Background Control: from n/a through 1.0.5.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-396f-8jhp-q236

больше 3 лет назад

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

EPSS: Низкий
github логотип

GHSA-3969-vr99-qg5h

почти 4 года назад

Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-3968-742r-3jq7

почти 4 года назад

SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.

EPSS: Низкий
github логотип

GHSA-3967-4r54-74c9

почти 2 года назад

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3966-q7xr-5r3x

почти 4 года назад

SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.

EPSS: Низкий
github логотип

GHSA-3966-f6p6-2qr9

17 дней назад

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25430.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3965-hpx2-q597

больше 1 года назад

Pug allows JavaScript code execution if an application accepts untrusted input

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3965-7vwp-wr38

почти 4 года назад

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

EPSS: Низкий
github логотип

GHSA-3963-94c4-r6r8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx() We don't currently validate that the values being set are within the range we advertised to userspace as being valid, do so and reject any values that are out of range.

EPSS: Низкий
github логотип

GHSA-3963-57mq-56wf

больше 3 лет назад

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

EPSS: Низкий
github логотип

GHSA-3962-w3j2-98vq

почти 2 года назад

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3962-mvm3-c84q

больше 3 лет назад

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3962-gjv5-4r4p

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-395x-wv32-44v5

около 3 лет назад

baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-395x-8q95-8h46

12 месяцев назад

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-395x-4p37-wm78

почти 3 года назад

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipulation of the argument sid leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223559.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-395x-3x8q-mv38

больше 3 лет назад

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-396g-cm65-2gh9

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-396g-3mmq-29wc

D-Link DIR-3040 prog.cgi SetIPv6PppoeSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21651.

CVSS3: 6.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-396f-r23h-8cqv

Cross-Site Request Forgery (CSRF) vulnerability in Johan Ström Background Control allows Path Traversal.This issue affects Background Control: from n/a through 1.0.5.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-396f-8jhp-q236

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3969-vr99-qg5h

Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."

63%
Средний
почти 4 года назад
github логотип
GHSA-3968-742r-3jq7

SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3967-4r54-74c9

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3966-q7xr-5r3x

SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3966-f6p6-2qr9

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25430.

CVSS3: 7
0%
Низкий
17 дней назад
github логотип
GHSA-3965-hpx2-q597

Pug allows JavaScript code execution if an application accepts untrusted input

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3965-7vwp-wr38

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3963-94c4-r6r8

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx() We don't currently validate that the values being set are within the range we advertised to userspace as being valid, do so and reject any values that are out of range.

больше 1 года назад
github логотип
GHSA-3963-57mq-56wf

A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3962-w3j2-98vq

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3962-mvm3-c84q

The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3962-gjv5-4r4p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-395x-wv32-44v5

baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability

CVSS3: 4.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-395x-8q95-8h46

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.

CVSS3: 3.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-395x-4p37-wm78

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipulation of the argument sid leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223559.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-395x-3x8q-mv38

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу