Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-343c-9x28-wq5v

почти 4 года назад

tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-343c-9jpq-vxvp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3439-fg7p-gc46

7 месяцев назад

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3439-3gp9-6qx5

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3439-28fg-g7gr

больше 3 лет назад

Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF parameter in captcha/index.php.

EPSS: Низкий
github логотип

GHSA-3438-w73j-w82h

почти 4 года назад

In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3437-6wr3-fc5g

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.

EPSS: Средний
github логотип

GHSA-3436-vqqc-85m3

больше 3 лет назад

There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3436-jvhw-jv5c

почти 2 года назад

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3435-jrhh-rq8g

больше 3 лет назад

USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.

EPSS: Низкий
github логотип

GHSA-3435-f6h9-64p7

10 месяцев назад

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3435-33m7-pm93

почти 2 года назад

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3434-hc3m-8mmm

больше 1 года назад

Reflected Cross-Site Scripting (XSS) in zenml

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3432-qjmc-vp87

около 3 лет назад

In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3432-fmrf-7vmh

8 месяцев назад

Chrome PHP is missing encoding in `CssSelector`

EPSS: Низкий
github логотип

GHSA-3432-988g-mrrm

почти 4 года назад

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3432-6f48-v5wj

5 месяцев назад

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-342x-54j8-cm6q

9 месяцев назад

Missing Authorization vulnerability in ValvePress Rankie allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rankie: from n/a through 1.8.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-342w-vxrh-ccxv

около 1 месяца назад

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function. This makes it possible for authenticated attackers, with Author-level access and above, to replace arbitrary media files from the WordPress Media Library.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-342w-jw3g-59cj

больше 3 лет назад

steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-343c-9x28-wq5v

tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-343c-9jpq-vxvp

Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3439-fg7p-gc46

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-3439-3gp9-6qx5

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3439-28fg-g7gr

Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF parameter in captcha/index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3438-w73j-w82h

In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3437-6wr3-fc5g

Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.

10%
Средний
почти 4 года назад
github логотип
GHSA-3436-vqqc-85m3

There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3436-jvhw-jv5c

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

CVSS3: 8.8
56%
Средний
почти 2 года назад
github логотип
GHSA-3435-jrhh-rq8g

USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3435-f6h9-64p7

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

CVSS3: 3.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-3435-33m7-pm93

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3434-hc3m-8mmm

Reflected Cross-Site Scripting (XSS) in zenml

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3432-qjmc-vp87

In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3432-fmrf-7vmh

Chrome PHP is missing encoding in `CssSelector`

0%
Низкий
8 месяцев назад
github логотип
GHSA-3432-988g-mrrm

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3432-6f48-v5wj

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-342x-54j8-cm6q

Missing Authorization vulnerability in ValvePress Rankie allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rankie: from n/a through 1.8.0.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-342w-vxrh-ccxv

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function. This makes it possible for authenticated attackers, with Author-level access and above, to replace arbitrary media files from the WordPress Media Library.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-342w-jw3g-59cj

steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу