Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-324f-g94h-3w6p

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-324f-g2g5-rj4m

больше 3 лет назад

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-324f-c4g7-9r7j

почти 2 года назад

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-324c-r2g2-547c

7 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3249-ch6f-5vrf

почти 2 года назад

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3248-f932-c76p

11 месяцев назад

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3248-f5xr-jwg7

больше 2 лет назад

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3248-52cq-vhgx

почти 4 года назад

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

EPSS: Низкий
github логотип

GHSA-3247-q928-6mr7

больше 3 лет назад

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

EPSS: Низкий
github логотип

GHSA-3247-hfh9-m3hv

больше 3 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3247-33gc-rgpq

почти 4 года назад

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3246-g44m-35rw

4 месяца назад

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3244-vj38-xw85

9 месяцев назад

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3244-jfpr-7px4

почти 4 года назад

The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3244-8mff-w398

около 3 лет назад

Reflected XSS in Gotify's /docs via import of outdated Swagger UI

EPSS: Низкий
github логотип

GHSA-3244-863h-59jf

8 месяцев назад

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3243-w5fh-rcj8

11 месяцев назад

Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3243-c96f-w7x3

больше 3 лет назад

The mintToken function of a smart contract implementation for WXSLToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3242-rqgf-8x5v

6 дней назад

A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be executed remotely. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3242-hvmp-wgvm

около 3 лет назад

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-324f-g94h-3w6p

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-324f-g2g5-rj4m

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-324f-c4g7-9r7j

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-324c-r2g2-547c

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3249-ch6f-5vrf

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3248-f932-c76p

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3248-f5xr-jwg7

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3248-52cq-vhgx

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3247-q928-6mr7

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3247-hfh9-m3hv

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3247-33gc-rgpq

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3246-g44m-35rw

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.

CVSS3: 6.7
0%
Низкий
4 месяца назад
github логотип
GHSA-3244-vj38-xw85

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3244-jfpr-7px4

The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-3244-8mff-w398

Reflected XSS in Gotify's /docs via import of outdated Swagger UI

около 3 лет назад
github логотип
GHSA-3244-863h-59jf

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-3243-w5fh-rcj8

Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3243-c96f-w7x3

The mintToken function of a smart contract implementation for WXSLToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3242-rqgf-8x5v

A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be executed remotely. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.

CVSS3: 5.3
0%
Низкий
6 дней назад
github логотип
GHSA-3242-hvmp-wgvm

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу