Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-334h-jmqc-fx27

больше 3 лет назад

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-334h-3www-4425

больше 1 года назад

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265073 was assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-334h-3w5w-cxp2

больше 3 лет назад

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-334g-hq35-7fwx

около 1 года назад

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-334g-63pm-w326

около 2 месяцев назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-67036. Reason: This record is a reservation duplicate of CVE-2025-67036. Notes: All CVE users should reference CVE-2025-67036 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

EPSS: Низкий
github логотип

GHSA-334f-5c7w-6p82

больше 3 лет назад

Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.

EPSS: Средний
github логотип

GHSA-3349-q488-4m7r

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duwasai Flashy allows Reflected XSS.This issue affects Flashy: from n/a through 1.2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3348-q8xc-86x9

больше 2 лет назад

Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3348-c2xh-h9pw

почти 4 года назад

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

EPSS: Низкий
github логотип

GHSA-3346-hwjm-fgpv

больше 3 лет назад

Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow an authenticated user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-3346-684m-gqjw

11 месяцев назад

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3346-5fc6-qhpc

больше 3 лет назад

Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.

EPSS: Низкий
github логотип

GHSA-3345-gfqq-q77j

больше 3 лет назад

GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3345-6fwj-mp93

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3345-56f6-jwpr

больше 3 лет назад

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.

EPSS: Низкий
github логотип

GHSA-3343-mpgf-85hp

больше 3 лет назад

RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3343-6cwg-x659

больше 3 лет назад

The mintToken function of a smart contract implementation for MomentumToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3343-583v-hgxx

больше 3 лет назад

TestLink 1.9.19 has XSS via the error.php message parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3342-4jqh-pxw7

почти 3 года назад

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-333x-qr3v-g4xx

почти 5 лет назад

Command injection in spritesheet-js

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-334h-jmqc-fx27

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-334h-3www-4425

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265073 was assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-334h-3w5w-cxp2

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-334g-hq35-7fwx

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-334g-63pm-w326

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-67036. Reason: This record is a reservation duplicate of CVE-2025-67036. Notes: All CVE users should reference CVE-2025-67036 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

около 2 месяцев назад
github логотип
GHSA-334f-5c7w-6p82

Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.

46%
Средний
больше 3 лет назад
github логотип
GHSA-3349-q488-4m7r

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duwasai Flashy allows Reflected XSS.This issue affects Flashy: from n/a through 1.2.1.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3348-q8xc-86x9

Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3348-c2xh-h9pw

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3346-hwjm-fgpv

Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow an authenticated user to potentially enable information disclosure via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3346-684m-gqjw

The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.

CVSS3: 5.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3346-5fc6-qhpc

Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3345-gfqq-q77j

GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3345-6fwj-mp93

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3345-56f6-jwpr

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3343-mpgf-85hp

RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3343-6cwg-x659

The mintToken function of a smart contract implementation for MomentumToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3343-583v-hgxx

TestLink 1.9.19 has XSS via the error.php message parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3342-4jqh-pxw7

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-333x-qr3v-g4xx

Command injection in spritesheet-js

CVSS3: 9.8
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу