Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-38gp-wr3c-cqw7

больше 3 лет назад

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-38gp-wf27-935r

больше 3 лет назад

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gp-jhv5-4hgh

больше 3 лет назад

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38gp-chjq-42jw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38gp-2mrc-f9cj

больше 3 лет назад

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gp-237c-7q54

почти 4 года назад

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

EPSS: Низкий
github логотип

GHSA-38gm-wvj3-rc26

около 3 лет назад

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gm-m6ww-x846

около 2 лет назад

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gj-h5v9-v9pm

11 месяцев назад

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gh-v47f-3r7c

почти 4 года назад

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-38gh-44mj-6cx9

больше 1 года назад

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38gf-rh2w-gmj7

больше 1 года назад

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38gf-q933-q62g

больше 1 года назад

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38gc-w4h9-7pmf

около 4 лет назад

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

EPSS: Низкий
github логотип

GHSA-38g9-r8v2-99xr

около 1 года назад

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38g9-g3gm-rjcm

больше 3 лет назад

Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38g8-fx3r-j23m

больше 3 лет назад

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38g8-fv8m-xfpr

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38g7-w2c7-wgjj

почти 4 года назад

SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.

EPSS: Низкий
github логотип

GHSA-38g7-cph9-j9g7

почти 4 года назад

Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38gp-wr3c-cqw7

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-wf27-935r

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-jhv5-4hgh

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-chjq-42jw

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-2mrc-f9cj

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-237c-7q54

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38gm-wvj3-rc26

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-38gm-m6ww-x846

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-38gj-h5v9-v9pm

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-38gh-v47f-3r7c

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

21%
Средний
почти 4 года назад
github логотип
GHSA-38gh-44mj-6cx9

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gf-q933-q62g

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gc-w4h9-7pmf

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

0%
Низкий
около 4 лет назад
github логотип
GHSA-38g9-r8v2-99xr

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38g9-g3gm-rjcm

Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-38g8-fx3r-j23m

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38g8-fv8m-xfpr

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

CVSS3: 7.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-38g7-w2c7-wgjj

SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-38g7-cph9-j9g7

Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу