Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xwv-25cq-66xr

9 месяцев назад

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xwr-53m3-98jw

почти 4 года назад

SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

EPSS: Низкий
github логотип

GHSA-2xwq-p62f-cjrm

больше 3 лет назад

PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xwq-h7r9-6w27

около 4 лет назад

Cross-site Scripting in kimai2

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2xwq-3g46-4j22

почти 4 года назад

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xwp-m7mq-7q3r

больше 5 лет назад

CLI does not correctly implement strict mode

EPSS: Низкий
github логотип

GHSA-2xwp-jx33-g2fj

больше 3 лет назад

NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xwp-gm9f-mwxv

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xwp-7j3p-c78x

больше 3 лет назад

Cross site scripting in SiteServer CMS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xwp-3v4p-x875

около 3 лет назад

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xwm-mmjj-m5x4

больше 3 лет назад

SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.

EPSS: Низкий
github логотип

GHSA-2xwm-j535-wh92

больше 3 лет назад

The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xwm-fqp4-pw7f

почти 4 года назад

Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.

EPSS: Низкий
github логотип

GHSA-2xwm-f2v4-92vh

почти 3 года назад

Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xwj-vx39-jqg9

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xwj-vc46-67hj

больше 1 года назад

Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2xwj-rw2w-xr5q

больше 3 лет назад

All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xwj-g27r-p9cr

больше 3 лет назад

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xwj-cxrx-46h4

больше 3 лет назад

Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.

EPSS: Низкий
github логотип

GHSA-2xwj-6795-v7p4

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xwv-25cq-66xr

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-2xwr-53m3-98jw

SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xwq-p62f-cjrm

PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwq-h7r9-6w27

Cross-site Scripting in kimai2

CVSS3: 4.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-2xwq-3g46-4j22

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2xwp-m7mq-7q3r

CLI does not correctly implement strict mode

больше 5 лет назад
github логотип
GHSA-2xwp-jx33-g2fj

NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwp-gm9f-mwxv

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2xwp-7j3p-c78x

Cross site scripting in SiteServer CMS

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwp-3v4p-x875

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2xwm-mmjj-m5x4

SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwm-j535-wh92

The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwm-fqp4-pw7f

Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xwm-f2v4-92vh

Transient DOS due to uncontrolled resource consumption in WLAN firmware when peer is freed in non qos state.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2xwj-vx39-jqg9

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through 2.1.33.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xwj-vc46-67hj

Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget allows Functionality Bypass.This issue affects Contact Form Builder, Contact Widget: from n/a through 2.1.7.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xwj-rw2w-xr5q

All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into ClearPass in the same browser.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwj-g27r-p9cr

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to be updated to point to an arbitrary SHA or another pull request outside of the fork repository. By establishing this incorrect reference in a PR, the restrictions that limit the Actions secrets sent a workflow from forks could be bypassed. This vulnerability affected GitHub Enterprise Server version 3.0.0, 3.0.0.rc2, and 3.0.0.rc1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwj-cxrx-46h4

Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwj-6795-v7p4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.

CVSS3: 7.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу