Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-38hx-3542-8fh3

больше 5 лет назад

Malicious code in `electorn`

EPSS: Низкий
github логотип

GHSA-38hw-368m-7jmg

больше 2 лет назад

Jenkins Ansible Plugin stores and displays secrets in plain text

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-38hv-wgp2-rgf9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.

EPSS: Низкий
github логотип

GHSA-38hv-w5wp-prfp

около 1 года назад

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38hv-gjp4-4fjh

почти 4 года назад

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-197960597

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38hr-xqm9-hhg9

больше 3 лет назад

An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38hq-wrmm-5f58

больше 3 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

EPSS: Низкий
github логотип

GHSA-38hp-jh3g-fr6g

4 месяца назад

A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-38hp-c2qq-q6vh

больше 3 лет назад

The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.

EPSS: Низкий
github логотип

GHSA-38hp-3f6w-vm5w

больше 3 лет назад

Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-38hm-hx7f-67mv

больше 3 лет назад

Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38hm-287h-q3wv

больше 1 года назад

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-38hj-x9j8-7x34

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38hj-p2p8-hhm2

больше 3 лет назад

HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.

EPSS: Средний
github логотип

GHSA-38hj-9hq2-w2gj

3 месяца назад

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38hj-4492-g88q

больше 3 лет назад

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38hh-r6wr-38f6

почти 4 года назад

yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

EPSS: Низкий
github логотип

GHSA-38hh-g82x-9mpc

больше 3 лет назад

Windows Media Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38hg-q2gf-cgvf

больше 2 лет назад

Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38hg-hvc8-v572

больше 1 года назад

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38hx-3542-8fh3

Malicious code in `electorn`

больше 5 лет назад
github логотип
GHSA-38hw-368m-7jmg

Jenkins Ansible Plugin stores and displays secrets in plain text

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38hv-wgp2-rgf9

Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hv-w5wp-prfp

Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-38hv-gjp4-4fjh

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-197960597

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-38hr-xqm9-hhg9

An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hq-wrmm-5f58

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hp-jh3g-fr6g

A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-38hp-c2qq-q6vh

The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hp-3f6w-vm5w

Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hm-hx7f-67mv

Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hm-287h-q3wv

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-38hj-x9j8-7x34

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-38hj-p2p8-hhm2

HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.

58%
Средний
больше 3 лет назад
github логотип
GHSA-38hj-9hq2-w2gj

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-38hj-4492-g88q

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hh-r6wr-38f6

yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

7%
Низкий
почти 4 года назад
github логотип
GHSA-38hh-g82x-9mpc

Windows Media Remote Code Execution Vulnerability

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-38hg-q2gf-cgvf

Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38hg-hvc8-v572

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу