Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xv6-7499-rm75

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2xv6-3vp8-pp7j

больше 1 года назад

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xv6-2j79-ghqr

около 1 года назад

Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xv5-3wp8-rwp3

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg87525.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xv4-x724-2399

больше 3 лет назад

An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2xv4-pww5-q9mh

почти 4 года назад

PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

EPSS: Низкий
github логотип

GHSA-2xv4-jrhf-gwvv

около 2 месяцев назад

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xv4-ch54-5wmx

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Bet sport Free allows Cross Site Request Forgery.This issue affects Bet sport Free: from n/a through 1.0.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xv4-c698-3v42

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2xv3-h762-ccxv

больше 6 лет назад

Out-of-bounds Read in concat-with-sourcemaps

EPSS: Низкий
github логотип

GHSA-2xv3-4xmw-7ff2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: blk-mq: make sure active queue usage is held for bio_integrity_prep() blk_integrity_unregister() can come if queue usage counter isn't held for one bio with integrity prepared, so this request may be completed with calling profile->complete_fn, then kernel panic. Another constraint is that bio_integrity_prep() needs to be called before bio merge. Fix the issue by: - call bio_integrity_prep() with one queue usage counter grabbed reliably - call bio_integrity_prep() before bio merge

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xv2-rwrw-35gw

4 месяца назад

A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2xrx-pwqh-wmrm

больше 2 лет назад

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2xrx-jfmm-qr34

больше 3 лет назад

Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xrw-2rc9-gpvm

больше 3 лет назад

An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 10 case.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xrv-qgm8-hh3g

больше 3 лет назад

An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bounds write via incorrect image data.

EPSS: Низкий
github логотип

GHSA-2xrv-7wfr-fxj6

около 2 лет назад

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xrv-6g4w-wcv4

больше 3 лет назад

Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

EPSS: Средний
github логотип

GHSA-2xrr-5f37-qww5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.

EPSS: Низкий
github логотип

GHSA-2xrq-v5g6-f94w

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xv6-7499-rm75

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7.

CVSS3: 8.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2xv6-3vp8-pp7j

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xv6-2j79-ghqr

Missing Authorization vulnerability in supsystic.com Data Tables Generator by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.36.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2xv5-3wp8-rwp3

A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg87525.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xv4-x724-2399

An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xv4-pww5-q9mh

PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2xv4-jrhf-gwvv

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2xv4-ch54-5wmx

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Bet sport Free allows Cross Site Request Forgery.This issue affects Bet sport Free: from n/a through 1.0.0.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2xv4-c698-3v42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2xv3-h762-ccxv

Out-of-bounds Read in concat-with-sourcemaps

больше 6 лет назад
github логотип
GHSA-2xv3-4xmw-7ff2

In the Linux kernel, the following vulnerability has been resolved: blk-mq: make sure active queue usage is held for bio_integrity_prep() blk_integrity_unregister() can come if queue usage counter isn't held for one bio with integrity prepared, so this request may be completed with calling profile->complete_fn, then kernel panic. Another constraint is that bio_integrity_prep() needs to be called before bio merge. Fix the issue by: - call bio_integrity_prep() with one queue usage counter grabbed reliably - call bio_integrity_prep() before bio merge

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xv2-rwrw-35gw

A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2xrx-pwqh-wmrm

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

CVSS3: 6.5
65%
Средний
больше 2 лет назад
github логотип
GHSA-2xrx-jfmm-qr34

Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrw-2rc9-gpvm

An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 10 case.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrv-qgm8-hh3g

An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bounds write via incorrect image data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrv-7wfr-fxj6

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2xrv-6g4w-wcv4

Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

11%
Средний
больше 3 лет назад
github логотип
GHSA-2xrr-5f37-qww5

Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrq-v5g6-f94w

Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу