Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3cgf-9m6x-pwwr

больше 4 лет назад

Data races in rusqlite

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cgf-8jcr-8fvv

больше 3 лет назад

Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

EPSS: Низкий
github логотип

GHSA-3cgc-jw8g-jq4x

8 месяцев назад

The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3cgc-cxx5-vcw5

около 3 лет назад

Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3cg9-jffc-jpcv

6 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3cg9-84j6-755p

больше 3 лет назад

A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted URL to the Client Manager Server. An exploit could allow the attacker to retrieve any file from the Cisco Workload Automation or Cisco Tidal Enterprise Scheduler Client Manager Server. This vulnerability affects the following products: Cisco Tidal Enterprise Scheduler Client Manager Server releases 6.2.1.435 and later, Cisco Workload Automation Client Manager Server releases 6.3.0.116 and later. Cisco Bug IDs: CSCvc90789.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3cg8-9wqp-7hg9

больше 3 лет назад

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.

EPSS: Низкий
github логотип

GHSA-3cg7-x7vx-225c

11 месяцев назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cg7-p7mp-2hcx

больше 3 лет назад

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cg6-xv3h-2wj2

больше 1 года назад

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3cg5-88qj-6x5f

почти 4 года назад

Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cg5-6rj7-9c9c

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cg4-vq2p-w876

почти 4 года назад

CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.

EPSS: Низкий
github логотип

GHSA-3cg4-jf33-6fwh

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3cg3-wjrx-v9jw

больше 3 лет назад

Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101.

EPSS: Низкий
github логотип

GHSA-3cg3-w3v4-rw4g

почти 4 года назад

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.

EPSS: Низкий
github логотип

GHSA-3cg3-vqjf-x53x

больше 3 лет назад

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3cg3-jw2v-vmvx

4 месяца назад

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3cg3-3mmr-w8hj

6 месяцев назад

Mattermost Confluence Plugin has Improper Validation of Specified Type of Input

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cg2-pp2v-hxh3

почти 4 года назад

SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cgf-9m6x-pwwr

Data races in rusqlite

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3cgf-8jcr-8fvv

Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cgc-jw8g-jq4x

The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3cgc-cxx5-vcw5

Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3cg9-jffc-jpcv

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4.

CVSS3: 7.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-3cg9-84j6-755p

A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted URL to the Client Manager Server. An exploit could allow the attacker to retrieve any file from the Cisco Workload Automation or Cisco Tidal Enterprise Scheduler Client Manager Server. This vulnerability affects the following products: Cisco Tidal Enterprise Scheduler Client Manager Server releases 6.2.1.435 and later, Cisco Workload Automation Client Manager Server releases 6.3.0.116 and later. Cisco Bug IDs: CSCvc90789.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg8-9wqp-7hg9

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg7-x7vx-225c

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3cg7-p7mp-2hcx

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg6-xv3h-2wj2

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVSS3: 7.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-3cg5-88qj-6x5f

Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg5-6rj7-9c9c

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3cg4-vq2p-w876

CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg4-jf33-6fwh

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 8
24%
Средний
10 месяцев назад
github логотип
GHSA-3cg3-wjrx-v9jw

Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg3-w3v4-rw4g

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg3-vqjf-x53x

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

CVSS3: 9.1
11%
Средний
больше 3 лет назад
github логотип
GHSA-3cg3-jw2v-vmvx

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5
0%
Низкий
4 месяца назад
github логотип
GHSA-3cg3-3mmr-w8hj

Mattermost Confluence Plugin has Improper Validation of Specified Type of Input

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3cg2-pp2v-hxh3

SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу