Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 024

Количество 301 024

github логотип

GHSA-26j2-cp35-2r7f

больше 3 лет назад

IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26j2-2wp8-h95h

почти 3 года назад

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26hx-v824-3wvf

больше 3 лет назад

** DISPUTED ** Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account."

EPSS: Низкий
github логотип

GHSA-26hx-622f-3855

1 день назад

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-26hw-262c-g9gc

больше 3 лет назад

Exposure of sensitive information vulnerability in Jenkins Black Duck Hub Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26hv-67m6-qjff

4 месяца назад

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26hr-q7pj-w334

больше 3 лет назад

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26hr-q2wp-rvc5

почти 2 года назад

User with permission to write actions can impersonate another user when auth token is configured in environment variable

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-26hr-9q73-x3wm

больше 3 лет назад

SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.

EPSS: Низкий
github логотип

GHSA-26hr-4x6c-5c7x

больше 1 года назад

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-26hq-r45f-3pr8

больше 3 лет назад

On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26hq-7m9g-65cf

больше 3 лет назад

Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26hq-7286-mg8f

больше 1 года назад

Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability

EPSS: Низкий
github логотип

GHSA-26hp-vwv6-p4qg

больше 1 года назад

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26hp-m9gv-2j62

около 1 года назад

Deserialization of Untrusted Data vulnerability in Gabriele Valenti Telecash Ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through 2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26hp-cgjj-m2j3

больше 1 года назад

fuel/core ImageMagick driver does not escape all shell arguments.

EPSS: Низкий
github логотип

GHSA-26hm-r6mg-963c

почти 4 года назад

SQL Injection in JeecgBoot

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26hm-gghq-x5rr

больше 3 лет назад

An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-26hm-cr9c-2627

больше 3 лет назад

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26hm-c7gj-q5mp

почти 4 года назад

Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26j2-cp35-2r7f

IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26j2-2wp8-h95h

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-26hx-v824-3wvf

** DISPUTED ** Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hx-622f-3855

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

CVSS3: 9.1
1 день назад
github логотип
GHSA-26hw-262c-g9gc

Exposure of sensitive information vulnerability in Jenkins Black Duck Hub Plugin

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hv-67m6-qjff

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-26hr-q7pj-w334

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hr-q2wp-rvc5

User with permission to write actions can impersonate another user when auth token is configured in environment variable

CVSS3: 6.2
почти 2 года назад
github логотип
GHSA-26hr-9q73-x3wm

SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26hr-4x6c-5c7x

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-26hq-r45f-3pr8

On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-26hq-7m9g-65cf

Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-26hq-7286-mg8f

Magento Patch SUPEE-9652 - Remote Code Execution using mail vulnerability

больше 1 года назад
github логотип
GHSA-26hp-vwv6-p4qg

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-26hp-m9gv-2j62

Deserialization of Untrusted Data vulnerability in Gabriele Valenti Telecash Ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through 2.2.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-26hp-cgjj-m2j3

fuel/core ImageMagick driver does not escape all shell arguments.

больше 1 года назад
github логотип
GHSA-26hm-r6mg-963c

SQL Injection in JeecgBoot

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-26hm-gghq-x5rr

An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.

CVSS3: 7.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-26hm-cr9c-2627

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hm-c7gj-q5mp

Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу