Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 694

Количество 301 694

github логотип

GHSA-2884-65gj-953q

больше 2 лет назад

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2884-62f5-6m65

11 месяцев назад

In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2883-9xj8-6c3x

больше 3 лет назад

An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2883-8qjj-chw7

больше 3 лет назад

The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2882-xfpf-chqj

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aelora iframe Wrapper allows DOM-Based XSS. This issue affects iframe Wrapper: from n/a through 0.1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-287x-hf3r-74ch

3 месяца назад

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-287x-c836-c4c9

больше 3 лет назад

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

EPSS: Низкий
github логотип

GHSA-287x-9rff-qvcg

4 месяца назад

Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-287x-6r2h-f9mw

3 месяца назад

UnoPim vulnerable to CSRF on Product edit feature and creation of other types

EPSS: Низкий
github логотип

GHSA-287x-67g2-7wf2

больше 3 лет назад

Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-287x-2333-6cmc

больше 2 лет назад

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-287w-9xcw-2gqp

больше 1 года назад

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some unknown functionality of the file /useratte/resmanage.php. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264530 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-287v-43mw-3ff7

больше 3 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-287r-v59r-8g28

больше 3 лет назад

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-287r-574x-f4h4

почти 4 года назад

RosarioSIS XSS Vulnerability

EPSS: Средний
github логотип

GHSA-287r-36rw-cfgc

больше 3 лет назад

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

EPSS: Средний
github логотип

GHSA-287q-rcxw-c7c5

3 месяца назад

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and Information disclosure.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-287q-jfcp-9vhv

почти 3 года назад

django-photologue vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-287m-mj3j-wvc9

больше 3 лет назад

A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.

EPSS: Низкий
github логотип

GHSA-287m-m4rw-v572

около 1 года назад

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2884-65gj-953q

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2884-62f5-6m65

In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)

CVSS3: 8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2883-9xj8-6c3x

An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2883-8qjj-chw7

The Yik Yak (aka com.yik.yak) application 2.0.002 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2882-xfpf-chqj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aelora iframe Wrapper allows DOM-Based XSS. This issue affects iframe Wrapper: from n/a through 0.1.1.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-287x-hf3r-74ch

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-287x-c836-c4c9

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-287x-9rff-qvcg

Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header

CVSS3: 4
0%
Низкий
4 месяца назад
github логотип
GHSA-287x-6r2h-f9mw

UnoPim vulnerable to CSRF on Product edit feature and creation of other types

0%
Низкий
3 месяца назад
github логотип
GHSA-287x-67g2-7wf2

Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-287x-2333-6cmc

Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-287w-9xcw-2gqp

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by this issue is some unknown functionality of the file /useratte/resmanage.php. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264530 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CVSS3: 6.3
2%
Низкий
больше 1 года назад
github логотип
GHSA-287v-43mw-3ff7

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-287r-v59r-8g28

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to possibly reveal and alter or forge its content, thereby escalating privileges.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-287r-574x-f4h4

RosarioSIS XSS Vulnerability

23%
Средний
почти 4 года назад
github логотип
GHSA-287r-36rw-cfgc

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

22%
Средний
больше 3 лет назад
github логотип
GHSA-287q-rcxw-c7c5

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and Information disclosure.

CVSS3: 8.4
0%
Низкий
3 месяца назад
github логотип
GHSA-287q-jfcp-9vhv

django-photologue vulnerable to Cross-site Scripting

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-287m-mj3j-wvc9

A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-287m-m4rw-v572

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

CVSS3: 8
0%
Низкий
около 1 года назад

Уязвимостей на страницу