Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-363c-mcgp-pjjx

около 1 года назад

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-363c-g524-mqxp

больше 3 лет назад

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

EPSS: Низкий
github логотип

GHSA-363c-9594-6hgr

больше 3 лет назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-363c-7592-r2hx

больше 3 лет назад

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3639-g9xw-jjg7

почти 4 года назад

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

EPSS: Низкий
github логотип

GHSA-3639-c3mm-hf33

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3639-77vf-hx6g

больше 2 лет назад

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3638-r263-v9hp

около 1 года назад

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-j9p9-fvfc

больше 1 года назад

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3638-4f56-qcf5

больше 3 лет назад

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3637-v6vq-xqqw

больше 3 лет назад

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3637-fm63-jqpr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3636-v8hq-c8g3

больше 2 лет назад

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3636-p8mw-vf54

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3636-hx62-pv26

больше 1 года назад

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3636-c8rc-p2rf

около 17 часов назад

Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3635-87f7-gfgj

больше 3 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3633-jv58-fg5j

больше 3 лет назад

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3633-g6mg-p6qq

10 месяцев назад

SurrealDB memory exhaustion via string::replace using regex

EPSS: Низкий
github логотип

GHSA-3633-c8j4-9489

больше 2 лет назад

Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-363c-mcgp-pjjx

Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-363c-g524-mqxp

An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-363c-9594-6hgr

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-363c-7592-r2hx

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3639-g9xw-jjg7

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3639-c3mm-hf33

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3639-77vf-hx6g

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3638-r263-v9hp

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3638-j9p9-fvfc

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3638-4f56-qcf5

There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3637-v6vq-xqqw

Harbor fails to validate the user permissions when updating tag retention policies

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3637-fm63-jqpr

Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3636-v8hq-c8g3

The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3636-p8mw-vf54

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3636-hx62-pv26

Zenario allows authenticated admin users to upload PDF files containing malicious code

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3636-c8rc-p2rf

Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
около 17 часов назад
github логотип
GHSA-3635-87f7-gfgj

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3633-jv58-fg5j

IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3633-g6mg-p6qq

SurrealDB memory exhaustion via string::replace using regex

10 месяцев назад
github логотип
GHSA-3633-c8j4-9489

Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу