Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 024

Количество 301 024

github логотип

GHSA-269m-c36j-r834

10 месяцев назад

Infinispan vulnerable to Insertion of Sensitive Information into Log File

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-269m-695x-j34p

около 7 лет назад

Apache Qpid Broker vulnerable to authentication port spoofing

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-269j-rg7r-j5rj

больше 3 лет назад

Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.

EPSS: Низкий
github логотип

GHSA-269j-r79f-hqvp

больше 3 лет назад

Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-269j-j44g-6c79

больше 3 лет назад

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

EPSS: Низкий
github логотип

GHSA-269j-j2cg-h6qp

больше 3 лет назад

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-269j-37ww-cmh3

4 месяца назад

Mezzanine CMS vulnerable to Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-269h-v9xg-7fq6

28 дней назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-269h-pcpx-q5mj

больше 3 лет назад

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-269h-hc79-qjpf

почти 2 года назад

LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-269h-2wf7-8247

больше 3 лет назад

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

EPSS: Низкий
github логотип

GHSA-269g-rg4h-9rr5

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-269g-pwp5-87pp

около 5 лет назад

TemporaryFolder on unix-like systems does not limit access to created files

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-269g-6r83-cfhc

больше 3 лет назад

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-269f-h4cx-j3fr

больше 1 года назад

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-269f-c6h8-6gv2

почти 3 года назад

A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-269f-8j25-5mp2

больше 3 лет назад

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-269c-5w5q-frxq

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-269c-4g57-c9vg

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2699-8r69-fq67

больше 2 лет назад

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-269m-c36j-r834

Infinispan vulnerable to Insertion of Sensitive Information into Log File

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-269m-695x-j34p

Apache Qpid Broker vulnerable to authentication port spoofing

CVSS3: 9.8
3%
Низкий
около 7 лет назад
github логотип
GHSA-269j-rg7r-j5rj

Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-269j-r79f-hqvp

Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-269j-j44g-6c79

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-269j-j2cg-h6qp

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-269j-37ww-cmh3

Mezzanine CMS vulnerable to Cross-site Scripting

CVSS3: 4.8
0%
Низкий
4 месяца назад
github логотип
GHSA-269h-v9xg-7fq6

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
0%
Низкий
28 дней назад
github логотип
GHSA-269h-pcpx-q5mj

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-269h-hc79-qjpf

LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-269h-2wf7-8247

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-269g-rg4h-9rr5

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-269g-pwp5-87pp

TemporaryFolder on unix-like systems does not limit access to created files

CVSS3: 4.4
0%
Низкий
около 5 лет назад
github логотип
GHSA-269g-6r83-cfhc

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-269f-h4cx-j3fr

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-269f-c6h8-6gv2

A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-269f-8j25-5mp2

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-269c-5w5q-frxq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-269c-4g57-c9vg

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2699-8r69-fq67

Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу