Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 710

Количество 315 710

github логотип

GHSA-388g-jwpg-x6j4

больше 5 лет назад

Cross-Site Scripting in swagger-ui

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-388g-hxhw-5c6q

12 месяцев назад

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-388g-95vj-q36x

почти 4 года назад

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-388c-v74f-rw5m

почти 4 года назад

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/AntivirusScanner.php: Line 124, scanNow($nodeObject) that can result in An attacker gaining admin access and can then execute arbitrary commands on the underlying OS. This attack appear to be exploitable via The attacker edits the Antivirus Command in the antivirus plugin, and executes the payload by uploading any file within Pydio.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-388c-p23g-jwxp

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <= 2.10.2 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-388c-mc6w-3p5w

больше 3 лет назад

A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-388c-fp3f-fvcv

около 1 месяца назад

This vulnerability allows a Backup or Tape Operator to write files as root.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-388c-58x8-m9gj

почти 2 года назад

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/app/service_crud.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-255374 is the identifier assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-388c-5882-28g4

больше 3 лет назад

Intesync Solismed 3.3sp allows Clickjacking.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3889-h6mq-grhq

около 1 года назад

Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected code is executed in their browser, which can result in the theft of sensitive information, identity theft or the execution of unauthorised actions on behalf of the affected user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3888-hq29-rm5x

12 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified allows Using Malicious Files. This issue affects Simplified: from n/a through 1.0.6.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3887-hqfw-78p7

почти 4 года назад

An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3887-7vpg-g78m

почти 3 года назад

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3886-rc87-ccgx

около 3 лет назад

A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3886-g7q7-mqpw

почти 4 года назад

An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3886-8ggm-q6g4

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3885-gg9g-8j6j

больше 3 лет назад

A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker who successfully makes an MSM user who has already established a session to MSM web interface clicks a forged link to the MSM web interface, e.g., the link is sent per E-Mail, could trick the user into downloading malicious software onto his computer. This issue affects: Hitachi Energy MSM V2.2 and prior versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3885-8gqc-3wpf

больше 3 лет назад

Potential leak of NuGet.org API key

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3884-hc6c-jwpv

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: orangefs: Fix kmemleak in orangefs_sysfs_init() When insert and remove the orangefs module, there are kobjects memory leaked as below: unreferenced object 0xffff88810f95af00 (size 64): comm "insmod", pid 783, jiffies 4294813439 (age 65.512s) hex dump (first 32 bytes): a0 83 af 01 81 88 ff ff 08 af 95 0f 81 88 ff ff ................ 08 af 95 0f 81 88 ff ff 00 00 00 00 00 00 00 00 ................ backtrace: [<0000000031ab7788>] kmalloc_trace+0x27/0xa0 [<000000005a6e4dfe>] orangefs_sysfs_init+0x42/0x3a0 [<00000000722645ca>] 0xffffffffa02780fe [<000000004232d9f7>] do_one_initcall+0x87/0x2a0 [<0000000054f22384>] do_init_module+0xdf/0x320 [<000000003263bdea>] load_module+0x2f98/0x3330 [<0000000052cd4153>] __do_sys_finit_module+0x113/0x1b0 [<00000000250ae02b>] do_syscall_64+0x35/0x80 [<00000000f11c03c7>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 unreferenced object 0x...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3884-6vq4-8grw

почти 4 года назад

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-388g-jwpg-x6j4

Cross-Site Scripting in swagger-ui

CVSS3: 6.5
больше 5 лет назад
github логотип
GHSA-388g-hxhw-5c6q

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-388g-95vj-q36x

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02; SIPROTEC 7SJ686 : All versions < V 4.83; SIPROTEC 7UT686 : All versions < V 4.01; SIPROTEC 7SD686 : All versions < V 4.03; SIPROTEC 7SJ66 : All versions < V 4.20. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain sensitive device information if network access was obtained.

CVSS3: 5.3
2%
Низкий
почти 4 года назад
github логотип
GHSA-388c-v74f-rw5m

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/AntivirusScanner.php: Line 124, scanNow($nodeObject) that can result in An attacker gaining admin access and can then execute arbitrary commands on the underlying OS. This attack appear to be exploitable via The attacker edits the Antivirus Command in the antivirus plugin, and executes the payload by uploading any file within Pydio.

CVSS3: 6.6
3%
Низкий
почти 4 года назад
github логотип
GHSA-388c-p23g-jwxp

Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <= 2.10.2 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-388c-mc6w-3p5w

A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-388c-fp3f-fvcv

This vulnerability allows a Backup or Tape Operator to write files as root.

CVSS3: 9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-388c-58x8-m9gj

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/app/service_crud.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-255374 is the identifier assigned to this vulnerability.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-388c-5882-28g4

Intesync Solismed 3.3sp allows Clickjacking.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3889-h6mq-grhq

Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected code is executed in their browser, which can result in the theft of sensitive information, identity theft or the execution of unauthorised actions on behalf of the affected user.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3888-hq29-rm5x

Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified allows Using Malicious Files. This issue affects Simplified: from n/a through 1.0.6.

CVSS3: 10
7%
Низкий
12 месяцев назад
github логотип
GHSA-3887-hqfw-78p7

An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3887-7vpg-g78m

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3886-rc87-ccgx

A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3886-g7q7-mqpw

An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3886-8ggm-q6g4

Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3885-gg9g-8j6j

A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker who successfully makes an MSM user who has already established a session to MSM web interface clicks a forged link to the MSM web interface, e.g., the link is sent per E-Mail, could trick the user into downloading malicious software onto his computer. This issue affects: Hitachi Energy MSM V2.2 and prior versions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3885-8gqc-3wpf

Potential leak of NuGet.org API key

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3884-hc6c-jwpv

In the Linux kernel, the following vulnerability has been resolved: orangefs: Fix kmemleak in orangefs_sysfs_init() When insert and remove the orangefs module, there are kobjects memory leaked as below: unreferenced object 0xffff88810f95af00 (size 64): comm "insmod", pid 783, jiffies 4294813439 (age 65.512s) hex dump (first 32 bytes): a0 83 af 01 81 88 ff ff 08 af 95 0f 81 88 ff ff ................ 08 af 95 0f 81 88 ff ff 00 00 00 00 00 00 00 00 ................ backtrace: [<0000000031ab7788>] kmalloc_trace+0x27/0xa0 [<000000005a6e4dfe>] orangefs_sysfs_init+0x42/0x3a0 [<00000000722645ca>] 0xffffffffa02780fe [<000000004232d9f7>] do_one_initcall+0x87/0x2a0 [<0000000054f22384>] do_init_module+0xdf/0x320 [<000000003263bdea>] load_module+0x2f98/0x3330 [<0000000052cd4153>] __do_sys_finit_module+0x113/0x1b0 [<00000000250ae02b>] do_syscall_64+0x35/0x80 [<00000000f11c03c7>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 unreferenced object 0x...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3884-6vq4-8grw

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу