Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xm6-wqqx-29gr

больше 3 лет назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2xm6-gr28-3f78

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save Improper use of secondary pointer (&dev->i2c_subip_regs) caused kernel crash and out-of-bounds error: BUG: KASAN: slab-out-of-bounds in _regmap_bulk_read+0x449/0x510 Write of size 4 at addr ffff888136005dc0 by task kworker/u33:5/5107 CPU: 3 UID: 0 PID: 5107 Comm: kworker/u33:5 Not tainted 6.16.0+ #3 PREEMPT(voluntary) Workqueue: async async_run_entry_fn Call Trace: <TASK> dump_stack_lvl+0x76/0xa0 print_report+0xd1/0x660 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? kasan_complete_mode_report_info+0x26/0x200 kasan_report+0xe1/0x120 ? _regmap_bulk_read+0x449/0x510 ? _regmap_bulk_read+0x449/0x510 __asan_report_store4_noabort+0x17/0x30 _regmap_bulk_read+0x449/0x510 ? __pfx__regmap_bulk_read+0x10/0x10 regmap_bulk_read+0x270/0x3d0 pio_complete+0x1ee/0x2c0 [intel_thc] ? __pfx_pio_complete+0x10/0x10 [intel_thc]...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xm6-ff93-jr99

8 месяцев назад

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.2 is able to address this issue. The identifier of the patch is db10ecb62ac832c1ed4924556d167efb9bc07fad. It is recommended to upgrade the affected component.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2xm5-7w7q-2rjh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page.

EPSS: Низкий
github логотип

GHSA-2xm2-xj2q-qgpj

больше 5 лет назад

receiving subscription objects with deleted session

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xm2-9fwc-4337

больше 3 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2xm2-23ff-p8ww

10 месяцев назад

Formie has XSS vulnerability for email notification content for preview

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2xjx-v99w-gqf3

больше 3 лет назад

Exposure of Sensitive Information in System.Net.Http

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xjx-542r-phch

3 дня назад

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block. Such manipulation leads to sql injection. The attack can be executed remotely. Upgrading to version 4.5 LTS and 5.0 is able to address this issue. You should upgrade the affected component.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2xjx-3p25-hm8x

почти 4 года назад

MiniUPnPd has information disclosure use of snprintf()

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xjw-j52v-f7gr

больше 1 года назад

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2xjw-f2qp-mmx6

почти 4 года назад

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xjw-c82q-7mpg

больше 3 лет назад

A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

EPSS: Низкий
github логотип

GHSA-2xjw-5437-xj2x

9 месяцев назад

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xjr-p7rw-gjm7

больше 3 лет назад

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

EPSS: Низкий
github логотип

GHSA-2xjr-g6rh-fxqf

почти 4 года назад

Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

EPSS: Низкий
github логотип

GHSA-2xjr-fp46-9fhh

почти 2 года назад

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xjq-x834-qrr3

12 дней назад

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.

EPSS: Низкий
github логотип

GHSA-2xjp-r9f7-cm2x

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-2xjp-jvqv-hvj5

больше 3 лет назад

Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xm6-wqqx-29gr

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xm6-gr28-3f78

In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save Improper use of secondary pointer (&dev->i2c_subip_regs) caused kernel crash and out-of-bounds error: BUG: KASAN: slab-out-of-bounds in _regmap_bulk_read+0x449/0x510 Write of size 4 at addr ffff888136005dc0 by task kworker/u33:5/5107 CPU: 3 UID: 0 PID: 5107 Comm: kworker/u33:5 Not tainted 6.16.0+ #3 PREEMPT(voluntary) Workqueue: async async_run_entry_fn Call Trace: <TASK> dump_stack_lvl+0x76/0xa0 print_report+0xd1/0x660 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? kasan_complete_mode_report_info+0x26/0x200 kasan_report+0xe1/0x120 ? _regmap_bulk_read+0x449/0x510 ? _regmap_bulk_read+0x449/0x510 __asan_report_store4_noabort+0x17/0x30 _regmap_bulk_read+0x449/0x510 ? __pfx__regmap_bulk_read+0x10/0x10 regmap_bulk_read+0x270/0x3d0 pio_complete+0x1ee/0x2c0 [intel_thc] ? __pfx_pio_complete+0x10/0x10 [intel_thc]...

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2xm6-ff93-jr99

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.2 is able to address this issue. The identifier of the patch is db10ecb62ac832c1ed4924556d167efb9bc07fad. It is recommended to upgrade the affected component.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2xm5-7w7q-2rjh

Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xm2-xj2q-qgpj

receiving subscription objects with deleted session

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
github логотип
GHSA-2xm2-9fwc-4337

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xm2-23ff-p8ww

Formie has XSS vulnerability for email notification content for preview

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-2xjx-v99w-gqf3

Exposure of Sensitive Information in System.Net.Http

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjx-542r-phch

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block. Such manipulation leads to sql injection. The attack can be executed remotely. Upgrading to version 4.5 LTS and 5.0 is able to address this issue. You should upgrade the affected component.

CVSS3: 4.7
0%
Низкий
3 дня назад
github логотип
GHSA-2xjx-3p25-hm8x

MiniUPnPd has information disclosure use of snprintf()

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2xjw-j52v-f7gr

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xjw-f2qp-mmx6

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2xjw-c82q-7mpg

A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjw-5437-xj2x

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-2xjr-p7rw-gjm7

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-2xjr-g6rh-fxqf

Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xjr-fp46-9fhh

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2xjq-x834-qrr3

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.

0%
Низкий
12 дней назад
github логотип
GHSA-2xjp-r9f7-cm2x

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

CVSS3: 2.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2xjp-jvqv-hvj5

Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу