Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-363f-hg5g-qwpf

9 месяцев назад

A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-363f-897q-jph9

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-363f-7q84-2cr6

больше 3 лет назад

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.

EPSS: Низкий
github логотип

GHSA-363c-mcgp-pjjx

около 1 года назад

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-363c-g524-mqxp

больше 3 лет назад

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

EPSS: Низкий
github логотип

GHSA-363c-9594-6hgr

больше 3 лет назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-363c-7592-r2hx

больше 3 лет назад

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3639-g9xw-jjg7

почти 4 года назад

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

EPSS: Низкий
github логотип

GHSA-3639-c3mm-hf33

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3639-77vf-hx6g

больше 2 лет назад

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3638-r263-v9hp

около 1 года назад

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-j9p9-fvfc

больше 1 года назад

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-4f56-qcf5

больше 3 лет назад

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3637-v6vq-xqqw

больше 3 лет назад

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3637-fm63-jqpr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3636-v8hq-c8g3

больше 2 лет назад

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3636-p8mw-vf54

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3636-hx62-pv26

больше 1 года назад

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3635-87f7-gfgj

больше 3 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3633-jv58-fg5j

больше 3 лет назад

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-363f-hg5g-qwpf

A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-363f-897q-jph9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-363f-7q84-2cr6

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-363c-mcgp-pjjx

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-363c-g524-mqxp

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-363c-9594-6hgr

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-363c-7592-r2hx

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3639-g9xw-jjg7

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3639-c3mm-hf33

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3639-77vf-hx6g

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3638-r263-v9hp

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3638-j9p9-fvfc

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3638-4f56-qcf5

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3637-v6vq-xqqw

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3637-fm63-jqpr

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3636-v8hq-c8g3

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3636-p8mw-vf54

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3636-hx62-pv26

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3635-87f7-gfgj

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3633-jv58-fg5j

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу