Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-34m5-2946-52jc

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34m4-9vvp-p7j9

12 месяцев назад

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument tid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34m3-97v7-926m

больше 3 лет назад

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-34jx-wx69-9x8v

почти 4 года назад

Symlink Attack in kubectl cp

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-34jx-q9xg-rr5x

около 2 лет назад

Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-34jw-gf29-7x45

5 месяцев назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jv-w46c-36jr

больше 3 лет назад

Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jv-m534-q8qr

больше 3 лет назад

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34jv-9f93-hq2f

почти 4 года назад

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-34jr-r2pr-95hh

около 1 года назад

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jq-f4vw-gcm5

почти 4 года назад

PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.

EPSS: Низкий
github логотип

GHSA-34jq-548x-m2x9

больше 4 лет назад

Improper Resource Shutdown or Release in TYPO3 extension

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34jq-3228-6mcp

больше 3 лет назад

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.

EPSS: Низкий
github логотип

GHSA-34jp-w7ww-7cwj

почти 2 года назад

A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259592.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34jm-h6vm-gxqp

почти 4 года назад

DNS cache poisoning via BIND, by predictable query IDs.

EPSS: Низкий
github логотип

GHSA-34jm-9965-j384

5 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34jm-95xh-4rx8

больше 3 лет назад

A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jj-j7vv-x8fp

почти 4 года назад

Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).

EPSS: Низкий
github логотип

GHSA-34jj-27w8-h7cm

больше 3 лет назад

Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34jh-p97f-mpxf

больше 1 года назад

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34m5-2946-52jc

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-34m4-9vvp-p7j9

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/updateroutine.php. The manipulation of the argument tid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-34m3-97v7-926m

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34jx-wx69-9x8v

Symlink Attack in kubectl cp

CVSS3: 5.5
49%
Средний
почти 4 года назад
github логотип
GHSA-34jx-q9xg-rr5x

Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-34jw-gf29-7x45

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

CVSS3: 9.8
3%
Низкий
5 месяцев назад
github логотип
GHSA-34jv-w46c-36jr

Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34jv-m534-q8qr

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

CVSS3: 5.3
10%
Низкий
больше 3 лет назад
github логотип
GHSA-34jv-9f93-hq2f

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."

61%
Средний
почти 4 года назад
github логотип
GHSA-34jr-r2pr-95hh

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.

CVSS3: 9.8
3%
Низкий
около 1 года назад
github логотип
GHSA-34jq-f4vw-gcm5

PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-34jq-548x-m2x9

Improper Resource Shutdown or Release in TYPO3 extension

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34jq-3228-6mcp

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34jp-w7ww-7cwj

A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259592.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-34jm-h6vm-gxqp

DNS cache poisoning via BIND, by predictable query IDs.

3%
Низкий
почти 4 года назад
github логотип
GHSA-34jm-9965-j384

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location information.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-34jm-95xh-4rx8

A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34jj-j7vv-x8fp

Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).

1%
Низкий
почти 4 года назад
github логотип
GHSA-34jj-27w8-h7cm

Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34jh-p97f-mpxf

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

CVSS3: 4.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу