Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38g8-fv8m-xfpr

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38g7-w2c7-wgjj

почти 4 года назад

SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.

EPSS: Низкий
github логотип

GHSA-38g7-cph9-j9g7

почти 4 года назад

Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter.

EPSS: Низкий
github логотип

GHSA-38g6-x6jv-jwff

больше 3 лет назад

Plone XSS Vulnerability

EPSS: Низкий
github логотип

GHSA-38g6-vx2q-23wm

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_buddy(). Based on code in mb_free_blocks(), fast commit replay can end up marking as free blocks that are already marked as such. This causes corruption of the buddy bitmap so we need to regenerate it in that case.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38g5-822j-7rr9

около 1 месяца назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-38g3-w7mj-hw2f

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

EPSS: Средний
github логотип

GHSA-38g3-58hf-r96c

больше 2 лет назад

Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may cause repeated HMS Core updates and cause services to fail.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38fw-5cvw-p8h6

больше 2 лет назад

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38fw-44gr-hrfp

около 1 года назад

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-38fw-2f98-cjmf

больше 3 лет назад

Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Oracle Diagnostics Interfaces.

EPSS: Низкий
github логотип

GHSA-38fr-v9v6-498x

больше 2 лет назад

A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38fr-qxq2-m645

больше 2 лет назад

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fr-2xrg-mwqm

4 месяца назад

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-38fq-h5hc-gwv8

больше 2 лет назад

Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fq-722f-5mfp

больше 3 лет назад

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38fp-9j49-g4gm

больше 3 лет назад

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38fm-xc5v-hgc5

около 3 лет назад

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38fm-hvrq-g6g6

больше 2 лет назад

The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38fm-2h4v-3qf4

около 2 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38g8-fv8m-xfpr

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

CVSS3: 7.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-38g7-w2c7-wgjj

SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-38g7-cph9-j9g7

Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-38g6-x6jv-jwff

Plone XSS Vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38g6-vx2q-23wm

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_buddy(). Based on code in mb_free_blocks(), fast commit replay can end up marking as free blocks that are already marked as such. This causes corruption of the buddy bitmap so we need to regenerate it in that case.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-38g5-822j-7rr9

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-38g3-w7mj-hw2f

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

16%
Средний
почти 4 года назад
github логотип
GHSA-38g3-58hf-r96c

Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may cause repeated HMS Core updates and cause services to fail.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38fw-5cvw-p8h6

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38fw-44gr-hrfp

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.

CVSS3: 8
0%
Низкий
около 1 года назад
github логотип
GHSA-38fw-2f98-cjmf

Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Oracle Diagnostics Interfaces.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38fr-v9v6-498x

A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38fr-qxq2-m645

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38fr-2xrg-mwqm

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

CVSS3: 5.1
0%
Низкий
4 месяца назад
github логотип
GHSA-38fq-h5hc-gwv8

Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38fq-722f-5mfp

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38fp-9j49-g4gm

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38fm-xc5v-hgc5

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

CVSS3: 5.4
5%
Низкий
около 3 лет назад
github логотип
GHSA-38fm-hvrq-g6g6

The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38fm-2h4v-3qf4

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу