Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 801

Количество 301 801

github логотип

GHSA-28wr-vmq3-227j

3 месяца назад

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-28wr-h897-6hmv

8 месяцев назад

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28wq-pxv7-mr7m

больше 3 лет назад

In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28wq-p9hh-3w4h

больше 3 лет назад

Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-28wp-2xch-xmx5

больше 3 лет назад

The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.

EPSS: Низкий
github логотип

GHSA-28wh-2mp5-4gp8

около 1 года назад

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28wg-r79p-3484

больше 3 лет назад

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

EPSS: Низкий
github логотип

GHSA-28wg-8gv4-mpjf

почти 2 года назад

Broken access control in Silverpeas

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-28wg-555g-fr2v

больше 3 лет назад

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28wf-q2m6-rjgv

5 месяцев назад

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-28wf-jx5m-6fhg

около 2 лет назад

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28wf-973p-g3gx

больше 3 лет назад

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

EPSS: Низкий
github логотип

GHSA-28wc-7mwv-p5h3

больше 3 лет назад

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28w9-vf5c-mw9p

больше 3 лет назад

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

EPSS: Низкий
github логотип

GHSA-28w9-qhgf-j4rh

3 месяца назад

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28w9-f394-mqfw

больше 3 лет назад

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

EPSS: Низкий
github логотип

GHSA-28w9-2v4x-592r

4 месяца назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28w7-pjc6-7h5m

больше 3 лет назад

SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.

EPSS: Низкий
github логотип

GHSA-28w7-9227-5wcm

20 дней назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-28w7-5v3f-jc8j

больше 3 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28wr-vmq3-227j

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-28wr-h897-6hmv

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-28wq-pxv7-mr7m

In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.

CVSS3: 7.5
10%
Низкий
больше 3 лет назад
github логотип
GHSA-28wq-p9hh-3w4h

Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28wp-2xch-xmx5

The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close actions, aka Bug ID CSCug97416.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28wh-2mp5-4gp8

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-28wg-r79p-3484

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28wg-8gv4-mpjf

Broken access control in Silverpeas

CVSS3: 4.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-28wg-555g-fr2v

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28wf-q2m6-rjgv

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-28wf-jx5m-6fhg

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-28wf-973p-g3gx

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28wc-7mwv-p5h3

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28w9-vf5c-mw9p

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28w9-qhgf-j4rh

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-28w9-f394-mqfw

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-28w9-2v4x-592r

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-28w7-pjc6-7h5m

SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28w7-9227-5wcm

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
0%
Низкий
20 дней назад
github логотип
GHSA-28w7-5v3f-jc8j

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу