Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27rc-6r2c-mc56

больше 3 лет назад

Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.

EPSS: Низкий
github логотип

GHSA-27rc-369w-4rpj

больше 3 лет назад

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-27r8-w6vh-wf65

больше 3 лет назад

SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-27r8-6jpp-p76v

больше 3 лет назад

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27r7-5v98-m3q3

11 месяцев назад

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. When used in conjunction with the plugin's import and code action feature, this vulnerability can be leveraged to execute arbitrary code.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-27r7-3m9x-r533

3 месяца назад

traQ Allows Insertion of Sensitive Information into Log File

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27r6-xq24-p9x8

около 1 года назад

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-27r6-qw3g-4x74

больше 3 лет назад

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element attributes.

EPSS: Низкий
github логотип

GHSA-27r6-6m95-4c69

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

EPSS: Низкий
github логотип

GHSA-27r5-q87w-8cff

почти 3 года назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-27r4-rp49-685c

больше 3 лет назад

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

EPSS: Низкий
github логотип

GHSA-27r4-945x-jq67

12 месяцев назад

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27r4-3wxx-xxj6

почти 2 года назад

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-27r3-f3mg-fxp8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.

EPSS: Низкий
github логотип

GHSA-27r3-85x4-pfqv

больше 1 года назад

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27r2-x487-q675

больше 1 года назад

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27r2-6rqh-xrg8

больше 1 года назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27qx-rrr4-rx3x

больше 3 лет назад

drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qualcomm internal bug CR483310.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27qx-pwhc-4j5g

больше 1 года назад

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-27qw-rmpj-379q

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: jfs: fix null ptr deref in dtInsertEntry [syzbot reported] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 RIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713 ... [Analyze] In dtInsertEntry(), when the pointer h has the same value as p, after writing name in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the previously true judgment "p->header.flag & BT-LEAF" to change to no after writing the name operation, this leads to entering an incorrect branch and accessing the uninitialized object ih when judging this condition for the second time. [Fix] After got the page, check fr...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27rc-6r2c-mc56

Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-27rc-369w-4rpj

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

CVSS3: 6.1
25%
Средний
больше 3 лет назад
github логотип
GHSA-27r8-w6vh-wf65

SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27r8-6jpp-p76v

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-27r7-5v98-m3q3

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. When used in conjunction with the plugin's import and code action feature, this vulnerability can be leveraged to execute arbitrary code.

CVSS3: 9.6
3%
Низкий
11 месяцев назад
github логотип
GHSA-27r7-3m9x-r533

traQ Allows Insertion of Sensitive Information into Log File

CVSS3: 5.9
0%
Низкий
3 месяца назад
github логотип
GHSA-27r6-xq24-p9x8

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-27r6-qw3g-4x74

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element attributes.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-27r6-6m95-4c69

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27r5-q87w-8cff

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-27r4-rp49-685c

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27r4-945x-jq67

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-27r4-3wxx-xxj6

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.

CVSS3: 8.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-27r3-f3mg-fxp8

Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27r3-85x4-pfqv

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-27r2-x487-q675

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-27r2-6rqh-xrg8

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-27qx-rrr4-rx3x

drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qualcomm internal bug CR483310.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27qx-pwhc-4j5g

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

CVSS3: 8.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-27qw-rmpj-379q

In the Linux kernel, the following vulnerability has been resolved: jfs: fix null ptr deref in dtInsertEntry [syzbot reported] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 RIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713 ... [Analyze] In dtInsertEntry(), when the pointer h has the same value as p, after writing name in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the previously true judgment "p->header.flag & BT-LEAF" to change to no after writing the name operation, this leads to entering an incorrect branch and accessing the uninitialized object ih when judging this condition for the second time. [Fix] After got the page, check fr...

CVSS3: 5.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу