Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 330

Количество 301 330

github логотип

GHSA-277h-hmwq-93fq

больше 3 лет назад

There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-277h-8wc5-7qfc

5 месяцев назад

An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-277g-784h-5869

больше 3 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:620:27.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-277f-xx4c-9mf5

больше 3 лет назад

Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-277f-37gw-9gmq

5 месяцев назад

raspap-webgui has a Directory Traversal vulnerability

EPSS: Низкий
github логотип

GHSA-277c-h7c7-c26c

9 месяцев назад

A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.0 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-277c-5vvj-9pwx

больше 1 года назад

Flooding Server with Thumbnail files

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2779-qh7w-73rg

больше 2 лет назад

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to clear the plugin's cache.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2779-2c23-rw2v

11 месяцев назад

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2778-cfx6-g2xp

больше 2 лет назад

Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-2777-x3fh-6ph7

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS).This issue affects StarCities E-Municipality Management: before 20250825.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2777-r7v2-pxc5

7 месяцев назад

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2777-r28v-7m99

почти 3 года назад

The Image Hover Effects WordPress plugin through 5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2777-2vq8-c4v4

больше 6 лет назад

SQL Injection in sequelize

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2776-m3xx-f2vf

больше 3 лет назад

radiance 3R9+20080530 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/opt.fmt, (b) /tmp/out#####.fmt, (c) /tmp/tf#####.dat, (d) /tmp/gsf#####, (e) /tmp/sc#####.sh, (f) /tmp/il#####.pic, (g) /tmp/tl#####.pic, (h) /tmp/ds#####.pic, (i) /tmp/tfa#####, and (j) /tmp/sed##### temporary files, related to the (1) optics2rad, (2) pdelta, (3) dayfact, and (4) raddepend scripts.

EPSS: Низкий
github логотип

GHSA-2776-h8x3-vrr7

10 месяцев назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2776-fr3j-r98m

почти 3 года назад

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2775-52x6-3w7f

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter.

EPSS: Низкий
github логотип

GHSA-2775-28vw-wjvg

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts allows Cross Site Request Forgery. This issue affects DN Footer Contacts: from n/a through 1.8.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2774-v47p-f5v6

больше 1 года назад

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-277h-hmwq-93fq

There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-277h-8wc5-7qfc

An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive information. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-277g-784h-5869

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:620:27.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-277f-xx4c-9mf5

Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-277f-37gw-9gmq

raspap-webgui has a Directory Traversal vulnerability

0%
Низкий
5 месяцев назад
github логотип
GHSA-277c-h7c7-c26c

A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.0 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-277c-5vvj-9pwx

Flooding Server with Thumbnail files

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2779-qh7w-73rg

The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it possible for unauthenticated attackers to clear the plugin's cache.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2779-2c23-rw2v

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2778-cfx6-g2xp

Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11

CVSS3: 5.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2777-x3fh-6ph7

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS).This issue affects StarCities E-Municipality Management: before 20250825.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2777-r7v2-pxc5

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2777-r28v-7m99

The Image Hover Effects WordPress plugin through 5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2777-2vq8-c4v4

SQL Injection in sequelize

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-2776-m3xx-f2vf

radiance 3R9+20080530 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/opt.fmt, (b) /tmp/out#####.fmt, (c) /tmp/tf#####.dat, (d) /tmp/gsf#####, (e) /tmp/sc#####.sh, (f) /tmp/il#####.pic, (g) /tmp/tl#####.pic, (h) /tmp/ds#####.pic, (i) /tmp/tfa#####, and (j) /tmp/sed##### temporary files, related to the (1) optics2rad, (2) pdelta, (3) dayfact, and (4) raddepend scripts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2776-h8x3-vrr7

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2776-fr3j-r98m

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2775-52x6-3w7f

Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2775-28vw-wjvg

Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts allows Cross Site Request Forgery. This issue affects DN Footer Contacts: from n/a through 1.8.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2774-v47p-f5v6

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

CVSS3: 9.8
3%
Низкий
больше 1 года назад

Уязвимостей на страницу