Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3cm9-r84w-4v7c

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3cm9-jrf5-h2cx

4 месяца назад

Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key

EPSS: Низкий
github логотип

GHSA-3cm9-h59j-r72g

5 месяцев назад

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cm9-2f69-3m66

больше 3 лет назад

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-3cm8-v4wq-9mhf

7 месяцев назад

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3cm8-v4mc-gppg

около 3 лет назад

Path traversal in binwalk

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3cm8-rv8m-x9gf

почти 2 года назад

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3cm8-c447-7fw4

11 месяцев назад

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3cm8-8gxq-6jr4

больше 3 лет назад

Windows Kernel Denial of Service Vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cm6-m5qg-w4cv

больше 3 лет назад

rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown other impact via a crafted text element in an SVG document.

EPSS: Низкий
github логотип

GHSA-3cm6-82pp-x646

больше 3 лет назад

An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3cm5-wpg3-v928

больше 3 лет назад

Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The component is: Incorrect calls to _ensure_auth() wrapper result in authentication-checking not being applied to al routes.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cm5-j5r2-wvm7

около 2 лет назад

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file iuclid6.exe of the component Desktop Installer. The manipulation leads to incorrect default permissions. The attack needs to be approached locally. VDB-251670 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3cm5-9xrj-gw96

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail replymail allows Stored XSS.This issue affects replyMail: from n/a through <= 1.2.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cm5-26fm-mwrv

больше 3 лет назад

An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3cm3-xc2x-9g73

11 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text Editor allows Remote Code Inclusion. This issue affects Visual Text Editor: from n/a through 1.2.1.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3cm3-9ccj-7mvq

около 4 лет назад

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

EPSS: Низкий
github логотип

GHSA-3cm3-4557-5h5h

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix potential leak in rtw89_append_probe_req_ie() Do `kfree_skb(new)` before `goto out` to prevent potential leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cm2-qc8f-9f2g

около 2 месяцев назад

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3cjx-w9jj-45qv

больше 3 лет назад

The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cookie could then be abused to gain access to the application.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cm9-r84w-4v7c

Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cm9-jrf5-h2cx

Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key

0%
Низкий
4 месяца назад
github логотип
GHSA-3cm9-h59j-r72g

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3cm9-2f69-3m66

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm8-v4wq-9mhf

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.

CVSS3: 6.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3cm8-v4mc-gppg

Path traversal in binwalk

CVSS3: 7.8
47%
Средний
около 3 лет назад
github логотип
GHSA-3cm8-rv8m-x9gf

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

CVSS3: 6.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-3cm8-c447-7fw4

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3cm8-8gxq-6jr4

Windows Kernel Denial of Service Vulnerability.

CVSS3: 5.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm6-m5qg-w4cv

rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown other impact via a crafted text element in an SVG document.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm6-82pp-x646

An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm5-wpg3-v928

Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The component is: Incorrect calls to _ensure_auth() wrapper result in authentication-checking not being applied to al routes.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm5-j5r2-wvm7

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file iuclid6.exe of the component Desktop Installer. The manipulation leads to incorrect default permissions. The attack needs to be approached locally. VDB-251670 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3cm5-9xrj-gw96

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail replymail allows Stored XSS.This issue affects replyMail: from n/a through <= 1.2.0.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3cm5-26fm-mwrv

An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cm3-xc2x-9g73

Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text Editor allows Remote Code Inclusion. This issue affects Visual Text Editor: from n/a through 1.2.1.

CVSS3: 9.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-3cm3-9ccj-7mvq

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

0%
Низкий
около 4 лет назад
github логотип
GHSA-3cm3-4557-5h5h

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix potential leak in rtw89_append_probe_req_ie() Do `kfree_skb(new)` before `goto out` to prevent potential leak.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3cm2-qc8f-9f2g

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3cjx-w9jj-45qv

The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cookie could then be abused to gain access to the application.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу