Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-3cvh-w666-7794

больше 3 лет назад

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cvg-mw7q-93pw

больше 3 лет назад

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

EPSS: Низкий
github логотип

GHSA-3cvg-mp22-q8rc

больше 2 лет назад

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3cvg-jfmm-2mw4

больше 2 лет назад

Missing Authorization in GitHub repository hamza417/inure prior to build88.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3cvg-j39v-pqwx

больше 2 лет назад

A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cvf-rq6j-j34q

почти 3 года назад

This candidate was in a CNA pool that was not assigned to any issues during 2021.

EPSS: Низкий
github логотип

GHSA-3cvf-fpq3-c29m

почти 3 года назад

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3cvf-6w83-9rc3

больше 3 лет назад

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cvf-5chq-5r99

3 месяца назад

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cvc-f83h-vhvc

больше 3 лет назад

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3cv9-jw4h-8r53

больше 1 года назад

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3cv9-2r4x-c3c5

12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-3cv8-m6fw-pjg4

больше 3 лет назад

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3cv8-hffv-cwf4

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cv8-f86g-8p35

почти 4 года назад

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-3cv8-cqpx-wc6m

больше 1 года назад

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cv7-mfff-4c27

около 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cv7-5j4c-h696

почти 4 года назад

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.

EPSS: Низкий
github логотип

GHSA-3cv6-xr26-rj48

больше 3 лет назад

The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3cv6-rq95-c6hf

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cvh-w666-7794

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow an unauthorized attacker to disclose information.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cvg-mw7q-93pw

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cvg-mp22-q8rc

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cvg-jfmm-2mw4

Missing Authorization in GitHub repository hamza417/inure prior to build88.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cvg-j39v-pqwx

A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening of crafted ogg file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cvf-rq6j-j34q

This candidate was in a CNA pool that was not assigned to any issues during 2021.

почти 3 года назад
github логотип
GHSA-3cvf-fpq3-c29m

Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3cvf-6w83-9rc3

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cvf-5chq-5r99

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3cvc-f83h-vhvc

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv9-jw4h-8r53

The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3cv9-2r4x-c3c5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

12 месяцев назад
github логотип
GHSA-3cv8-m6fw-pjg4

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.

CVSS3: 6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv8-hffv-cwf4

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affects an unknown part of the file /whbs/admin/?page=user of the component Staff User Profile. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205815.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv8-f86g-8p35

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cv8-cqpx-wc6m

IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3cv7-mfff-4c27

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3cv7-5j4c-h696

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cv6-xr26-rj48

The Live TV Browser (aka com.wHDSmartBrowser) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv6-rq95-c6hf

Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу