Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32r9-qhg6-prph

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-32r9-2j7h-3vqq

больше 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-32r8-wpf6-r2gw

почти 2 года назад

A vulnerability classified as critical was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256951. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-32r8-8mcq-93v7

почти 4 года назад

Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.

EPSS: Средний
github логотип

GHSA-32r8-54hf-c9p3

около 1 года назад

unstructured XML External Entity (XXE)

EPSS: Низкий
github логотип

GHSA-32r8-256r-q9p6

почти 4 года назад

In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32r7-p8r7-9vwj

больше 2 лет назад

Missing Authorization in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-32r7-mgwg-67wq

больше 3 лет назад

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-32r6-9grj-4wcv

почти 4 года назад

Unspecified vulnerability in Hitachi DABroker before 03-02-/D and Cosminexus DABroker before 02-04-/C and 03-05-/E allows remote attackers to cause a denial of service (connection prevention) by sending "data unexpectedly through a port."

EPSS: Низкий
github логотип

GHSA-32r6-5q68-q96f

больше 3 лет назад

The affected product is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32r5-g2qx-7q77

больше 2 лет назад

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-32r5-6c8g-f64h

больше 3 лет назад

The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.

EPSS: Низкий
github логотип

GHSA-32r3-xpw6-2rr3

почти 4 года назад

Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

EPSS: Низкий
github логотип

GHSA-32r3-r3v8-gffr

почти 4 года назад

PHP remote file inclusion vulnerability in users_popupL.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the From parameter.

EPSS: Низкий
github логотип

GHSA-32r3-qw98-mc7h

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/enable or (2) disable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/disable. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

EPSS: Низкий
github логотип

GHSA-32r3-gj72-h3p2

больше 1 года назад

A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-32r3-57hp-cgfw

около 2 лет назад

EverShop at risk to unauthorized access via weak HMAC secret

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-32r2-xfqh-9qx6

больше 1 года назад

An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32r2-x7ch-xmj2

больше 1 года назад

Substance3D - Stager versions 3.0.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32r2-rwm4-hqgg

больше 3 лет назад

The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32r9-qhg6-prph

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX Product Feed for WooCommerce allows SQL Injection. This issue affects ELEX Product Feed for WooCommerce: from n/a through 3.1.2.

CVSS3: 7.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-32r9-2j7h-3vqq

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVSS3: 7.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-32r8-wpf6-r2gw

A vulnerability classified as critical was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256951. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-32r8-8mcq-93v7

Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.

23%
Средний
почти 4 года назад
github логотип
GHSA-32r8-54hf-c9p3

unstructured XML External Entity (XXE)

0%
Низкий
около 1 года назад
github логотип
GHSA-32r8-256r-q9p6

In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-32r7-p8r7-9vwj

Missing Authorization in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32r7-mgwg-67wq

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32r6-9grj-4wcv

Unspecified vulnerability in Hitachi DABroker before 03-02-/D and Cosminexus DABroker before 02-04-/C and 03-05-/E allows remote attackers to cause a denial of service (connection prevention) by sending "data unexpectedly through a port."

1%
Низкий
почти 4 года назад
github логотип
GHSA-32r6-5q68-q96f

The affected product is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32r5-g2qx-7q77

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-32r5-6c8g-f64h

The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32r3-xpw6-2rr3

Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

2%
Низкий
почти 4 года назад
github логотип
GHSA-32r3-r3v8-gffr

PHP remote file inclusion vulnerability in users_popupL.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the From parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32r3-qw98-mc7h

Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/enable or (2) disable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/disable. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32r3-gj72-h3p2

A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-32r3-57hp-cgfw

EverShop at risk to unauthorized access via weak HMAC secret

CVSS3: 7.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-32r2-xfqh-9qx6

An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-32r2-x7ch-xmj2

Substance3D - Stager versions 3.0.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-32r2-rwm4-hqgg

The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу