Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2xjx-3p25-hm8x

почти 4 года назад

MiniUPnPd has information disclosure use of snprintf()

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xjw-j52v-f7gr

больше 1 года назад

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2xjw-f2qp-mmx6

почти 4 года назад

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xjw-c82q-7mpg

больше 3 лет назад

A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

EPSS: Низкий
github логотип

GHSA-2xjw-5437-xj2x

9 месяцев назад

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xjr-p7rw-gjm7

больше 3 лет назад

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

EPSS: Низкий
github логотип

GHSA-2xjr-g6rh-fxqf

почти 4 года назад

Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

EPSS: Низкий
github логотип

GHSA-2xjr-fp46-9fhh

больше 1 года назад

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xjq-x834-qrr3

11 дней назад

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.

EPSS: Низкий
github логотип

GHSA-2xjp-r9f7-cm2x

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-2xjp-jvqv-hvj5

больше 3 лет назад

Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий
github логотип

GHSA-2xjp-g4vr-mgh3

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.2.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2xjp-8pmx-7mmj

больше 3 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

EPSS: Низкий
github логотип

GHSA-2xjj-5x6h-8vmf

больше 8 лет назад

Cross-site Scripting in actionpack

EPSS: Низкий
github логотип

GHSA-2xjj-2wcr-mj9m

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.

EPSS: Низкий
github логотип

GHSA-2xjh-cwp8-55q6

больше 2 лет назад

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xjh-35wj-vw46

больше 3 лет назад

Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, aka "Skype for Business Elevation of Privilege Vulnerability."

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2xjh-34g7-vxf5

около 1 года назад

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2xjg-x2hw-6m93

6 месяцев назад

A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_title.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be performed from a remote location. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xjg-vr83-9jg7

около 1 года назад

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xjx-3p25-hm8x

MiniUPnPd has information disclosure use of snprintf()

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2xjw-j52v-f7gr

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xjw-f2qp-mmx6

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2xjw-c82q-7mpg

A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjw-5437-xj2x

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-2xjr-p7rw-gjm7

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjr-g6rh-fxqf

Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xjr-fp46-9fhh

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xjq-x834-qrr3

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.

0%
Низкий
11 дней назад
github логотип
GHSA-2xjp-r9f7-cm2x

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2xjp-jvqv-hvj5

Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjp-g4vr-mgh3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.2.

CVSS3: 9.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2xjp-8pmx-7mmj

Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjj-5x6h-8vmf

Cross-site Scripting in actionpack

0%
Низкий
больше 8 лет назад
github логотип
GHSA-2xjj-2wcr-mj9m

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjh-cwp8-55q6

Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2xjh-35wj-vw46

Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, aka "Skype for Business Elevation of Privilege Vulnerability."

CVSS3: 8.8
11%
Средний
больше 3 лет назад
github логотип
GHSA-2xjh-34g7-vxf5

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 7.2
1%
Низкий
около 1 года назад
github логотип
GHSA-2xjg-x2hw-6m93

A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_title.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be performed from a remote location. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2xjg-vr83-9jg7

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

CVSS3: 9.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу