Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27wf-832r-r7vc

около 3 лет назад

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27wf-5967-98gx

12 месяцев назад

Kubernetes kubelet arbitrary command execution

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-27wf-58x2-9c98

больше 3 лет назад

In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-27wf-3ww8-gq93

больше 3 лет назад

The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27wc-fr9j-8x58

больше 3 лет назад

A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27w9-h9rx-p7c5

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-27w7-4rrm-p796

больше 3 лет назад

An issue was discovered in libthulac.so in THULAC through 2018-02-25. "operator delete" is used with "operator new[]" in the TaggingLearner class in include/cb_tagging_learner.h, possibly leading to memory corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27w7-2jg3-x45x

6 месяцев назад

A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27w6-8m77-x3qf

больше 1 года назад

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-27w5-gj5q-82fv

около 1 месяца назад

@nubosoftware/node-static failure to catch exception can result in server crash

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27w5-9p4f-w4h8

больше 3 лет назад

A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in potential code execution. An attacker can send a specific .PSD file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27w3-xhwh-5xw4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

EPSS: Низкий
github логотип

GHSA-27w2-xhhr-rp5p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

EPSS: Низкий
github логотип

GHSA-27w2-gfcm-69mr

больше 2 лет назад

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-27vx-r33r-rh7x

больше 3 лет назад

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27vr-8fpq-79vm

больше 3 лет назад

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27vr-69mf-gx49

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

EPSS: Низкий
github логотип

GHSA-27vr-5h5p-w59c

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27vr-24cc-98h4

больше 1 года назад

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-27vq-mhjm-v9gc

больше 3 лет назад

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27wf-832r-r7vc

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-27wf-5967-98gx

Kubernetes kubelet arbitrary command execution

CVSS3: 8.1
23%
Средний
12 месяцев назад
github логотип
GHSA-27wf-58x2-9c98

In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

CVSS3: 6.5
34%
Средний
больше 3 лет назад
github логотип
GHSA-27wf-3ww8-gq93

The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27wc-fr9j-8x58

A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27w9-h9rx-p7c5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.

CVSS3: 9.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-27w7-4rrm-p796

An issue was discovered in libthulac.so in THULAC through 2018-02-25. "operator delete" is used with "operator new[]" in the TaggingLearner class in include/cb_tagging_learner.h, possibly leading to memory corruption.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w7-2jg3-x45x

A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-27w6-8m77-x3qf

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.

CVSS3: 3.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-27w5-gj5q-82fv

@nubosoftware/node-static failure to catch exception can result in server crash

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-27w5-9p4f-w4h8

A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in potential code execution. An attacker can send a specific .PSD file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w3-xhwh-5xw4

Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w2-xhhr-rp5p

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w2-gfcm-69mr

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27vx-r33r-rh7x

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-8fpq-79vm

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-69mf-gx49

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-5h5p-w59c

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-27vr-24cc-98h4

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-27vq-mhjm-v9gc

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу