Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-348f-gwqg-3m3w

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-348c-hvj3-g7hp

почти 4 года назад

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

EPSS: Низкий
github логотип

GHSA-3489-8qg3-xgj4

больше 3 лет назад

This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

EPSS: Низкий
github логотип

GHSA-3487-3j7c-7gwj

около 2 лет назад

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3486-w28q-g6jc

почти 4 года назад

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

EPSS: Низкий
github логотип

GHSA-3486-rvxc-hrrj

больше 3 лет назад

gitblame susceptible to command injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3486-2953-r9fc

24 дня назад

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3485-7x7c-qrw2

больше 3 лет назад

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3485-35jp-jwmx

больше 2 лет назад

axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3484-rr8g-54gq

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3484-2rvh-885x

почти 2 года назад

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-19724.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3483-fv4j-8x97

больше 3 лет назад

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

EPSS: Низкий
github логотип

GHSA-3483-88xw-5g3h

11 месяцев назад

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3483-6grv-x2wh

больше 3 лет назад

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

EPSS: Низкий
github логотип

GHSA-3482-hrx3-vgcg

больше 3 лет назад

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Средний
github логотип

GHSA-3482-g6h6-r8v3

5 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3482-8qrw-5xpw

почти 4 года назад

Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

EPSS: Низкий
github логотип

GHSA-3482-6g24-6chg

больше 3 лет назад

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

EPSS: Низкий
github логотип

GHSA-3482-49mc-jhqp

почти 3 года назад

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/service_requests/manage_inventory.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226104.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3482-3whx-826m

больше 2 лет назад

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-348f-gwqg-3m3w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-348c-hvj3-g7hp

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3489-8qg3-xgj4

This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3487-3j7c-7gwj

Mattermost Uncontrolled Resource Consumption vulnerability

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3486-w28q-g6jc

Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3486-rvxc-hrrj

gitblame susceptible to command injection

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3486-2953-r9fc

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.

CVSS3: 8.2
0%
Низкий
24 дня назад
github логотип
GHSA-3485-7x7c-qrw2

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3485-35jp-jwmx

axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows attackers to cause a Denial of Service (DoS) when parsing a private key.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3484-rr8g-54gq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3484-2rvh-885x

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-19724.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3483-fv4j-8x97

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3483-88xw-5g3h

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

CVSS3: 3.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3483-6grv-x2wh

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3482-hrx3-vgcg

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

39%
Средний
больше 3 лет назад
github логотип
GHSA-3482-g6h6-r8v3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection. This issue affects Tutor LMS: from n/a through 3.7.4.

CVSS3: 7.6
0%
Низкий
5 месяцев назад
github логотип
GHSA-3482-8qrw-5xpw

Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3482-6g24-6chg

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3482-49mc-jhqp

A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/service_requests/manage_inventory.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226104.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3482-3whx-826m

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу