Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38m7-3q3q-x4xv

4 месяца назад

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38m6-xrq9-23c3

около 4 лет назад

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

EPSS: Низкий
github логотип

GHSA-38m6-gw8w-cmvr

больше 3 лет назад

Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-38m5-j785-6vrx

больше 3 лет назад

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-38m5-hfpr-wjwh

почти 2 года назад

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-38m4-v8gh-988g

больше 3 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in util-print.c:tok2strbuf().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38m3-mrrg-hx5g

больше 3 лет назад

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38m3-4jxp-wf6g

больше 3 лет назад

A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38m2-vr6g-8c94

около 3 лет назад

Apache Sling App CMS vulnerable to reflected Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38jx-wppr-r4q4

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.

EPSS: Низкий
github логотип

GHSA-38jw-wfq7-q7m7

больше 3 лет назад

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.

EPSS: Низкий
github логотип

GHSA-38jw-g2qx-4286

3 месяца назад

KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-38jw-6m6v-pmqm

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-38jw-3g8c-mmg7

больше 3 лет назад

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.

EPSS: Низкий
github логотип

GHSA-38jv-hg5q-hg9r

больше 1 года назад

The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38jv-5279-wg99

около 1 месяца назад

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38jv-4fq4-q7qq

около 4 лет назад

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

EPSS: Низкий
github логотип

GHSA-38jr-m6hg-2c25

больше 3 лет назад

RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.

EPSS: Низкий
github логотип

GHSA-38jr-7vx6-v3p4

больше 3 лет назад

Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to the IUSR account, which has restricted permission and is unable to make major system changes. An attempted attack requires user authentication.

EPSS: Низкий
github логотип

GHSA-38jr-793m-8jh2

больше 3 лет назад

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38m7-3q3q-x4xv

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-38m6-xrq9-23c3

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

0%
Низкий
около 4 лет назад
github логотип
GHSA-38m6-gw8w-cmvr

Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38m5-j785-6vrx

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38m5-hfpr-wjwh

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-38m4-v8gh-988g

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in util-print.c:tok2strbuf().

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38m3-mrrg-hx5g

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38m3-4jxp-wf6g

A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38m2-vr6g-8c94

Apache Sling App CMS vulnerable to reflected Cross-site Scripting

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-38jx-wppr-r4q4

Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38jw-wfq7-q7m7

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38jw-g2qx-4286

KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

CVSS3: 4.7
0%
Низкий
3 месяца назад
github логотип
GHSA-38jw-6m6v-pmqm

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38jw-3g8c-mmg7

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38jv-hg5q-hg9r

The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-38jv-5279-wg99

Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-38jv-4fq4-q7qq

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

0%
Низкий
около 4 лет назад
github логотип
GHSA-38jr-m6hg-2c25

RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38jr-7vx6-v3p4

Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to the IUSR account, which has restricted permission and is unable to make major system changes. An attempted attack requires user authentication.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-38jr-793m-8jh2

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу