Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3cc4-93g3-9qw4

8 месяцев назад

A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-course.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3cc4-79qf-47r2

8 месяцев назад

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This issue affects some unknown processing of the file /bwdate-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3cc4-4ggr-8jcr

больше 3 лет назад

Windows DNS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28328.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3cc4-3f86-q6qh

около 1 года назад

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cc3-x3hg-mxrx

больше 3 лет назад

The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-3cc3-r774-p8q6

больше 3 лет назад

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via username[0] to the default URI, because of includes/authenticate.inc.php.

EPSS: Низкий
github логотип

GHSA-3cc2-9qw3-rg33

больше 3 лет назад

Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

EPSS: Низкий
github логотип

GHSA-3c9x-f53x-v89c

больше 3 лет назад

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3c9x-2mx6-v84j

больше 3 лет назад

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c9v-fv3c-v7rc

около 2 лет назад

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c9v-5fr8-87x5

больше 1 года назад

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3c9r-w7qx-rq3w

почти 3 года назад

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c9r-9m8x-7j76

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

EPSS: Низкий
github логотип

GHSA-3c9r-8wrp-84w3

больше 2 лет назад

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c9q-xrh4-q9x9

больше 3 лет назад

The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3c9q-w3p6-49h3

больше 3 лет назад

Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis.

EPSS: Низкий
github логотип

GHSA-3c9p-wgx8-74fj

почти 4 года назад

CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/hikaye.mdb.

EPSS: Низкий
github логотип

GHSA-3c9p-hxf7-xpc6

почти 4 года назад

SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.

EPSS: Низкий
github логотип

GHSA-3c9m-5j33-vjf4

больше 3 лет назад

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c9m-2jj9-hx36

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: cipso: Fix data-races around sysctl. While reading cipso sysctl variables, they can be changed concurrently. So, we need to add READ_ONCE() to avoid data-races.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cc4-93g3-9qw4

A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-course.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3cc4-79qf-47r2

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This issue affects some unknown processing of the file /bwdate-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3cc4-4ggr-8jcr

Windows DNS Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28328.

CVSS3: 6.5
17%
Средний
больше 3 лет назад
github логотип
GHSA-3cc4-3f86-q6qh

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3cc3-x3hg-mxrx

The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cc3-r774-p8q6

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via username[0] to the default URI, because of includes/authenticate.inc.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cc2-9qw3-rg33

Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9x-f53x-v89c

FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

CVSS3: 9.8
69%
Средний
больше 3 лет назад
github логотип
GHSA-3c9x-2mx6-v84j

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9v-fv3c-v7rc

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3c9v-5fr8-87x5

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3c9r-w7qx-rq3w

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3c9r-9m8x-7j76

Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9r-8wrp-84w3

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c9q-xrh4-q9x9

The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9q-w3p6-49h3

Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9p-wgx8-74fj

CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/hikaye.mdb.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c9p-hxf7-xpc6

SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3c9m-5j33-vjf4

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c9m-2jj9-hx36

In the Linux kernel, the following vulnerability has been resolved: cipso: Fix data-races around sysctl. While reading cipso sysctl variables, they can be changed concurrently. So, we need to add READ_ONCE() to avoid data-races.

CVSS3: 4.7
0%
Низкий
11 месяцев назад

Уязвимостей на страницу