Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2x59-2xmg-fgcx

больше 3 лет назад

WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x59-2w3w-3ccw

3 месяца назад

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2x59-22p6-6v87

больше 3 лет назад

An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2x58-77jw-wgpw

почти 4 года назад

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.

EPSS: Низкий
github логотип

GHSA-2x57-wp24-3gfm

около 1 года назад

Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-2x57-vxvc-jh3v

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: bpf: account for current allocated stack depth in widen_imprecise_scalars() The usage pattern for widen_imprecise_scalars() looks as follows: prev_st = find_prev_entry(env, ...); queued_st = push_stack(...); widen_imprecise_scalars(env, prev_st, queued_st); Where prev_st is an ancestor of the queued_st in the explored states tree. This ancestor is not guaranteed to have same allocated stack depth as queued_st. E.g. in the following case: def main(): for i in 1..2: foo(i) // same callsite, differnt param def foo(i): if i == 1: use 128 bytes of stack iterator based loop Here, for a second 'foo' call prev_st->allocated_stack is 128, while queued_st->allocated_stack is much smaller. widen_imprecise_scalars() needs to take this into account and avoid accessing bpf_verifier_state->frame[*]->stack out of bounds.

EPSS: Низкий
github логотип

GHSA-2x56-wxfv-qqrm

больше 1 года назад

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x55-mg9r-24f7

больше 3 лет назад

Magento 2 Community Edition RCE Vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2x55-cxhq-4m7q

почти 2 года назад

SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x54-j4m3-r6wx

около 7 лет назад

sqla-yaml-fixtures is vulnerable to Code Injection

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x54-cv5h-7995

7 месяцев назад

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2x53-xr45-qcv3

почти 4 года назад

SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.

EPSS: Низкий
github логотип

GHSA-2x53-x293-3jfh

больше 3 лет назад

A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x53-jv7f-c2x5

больше 1 года назад

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2x52-8f29-7cjr

почти 2 года назад

Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2x4x-xw83-gw6x

около 1 года назад

Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2x4x-fh63-4wpq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2x4x-73fj-7gr8

больше 3 лет назад

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x4w-j73f-g9qq

больше 2 лет назад

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2x4w-2j26-p5hx

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the MIDIStreaming endpoint descriptors are filled with the correct information, bNumEmbMIDIJack and bLength are set incorrectly in these descriptors. This does not matter when the numbers of in and out ports are equal, but when they differ the host will receive broken descriptors with uninitialized stack memory leaking into the descriptor for whichever value is smaller. The precise meaning of "in" and "out" in the port counts is not clearly defined and can be confusing. But elsewhere the driver consistently uses this to match the USB meaning of IN and OUT viewed from the host, so that "in" ports send data to the host and "out" ports receive data from it.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2x59-2xmg-fgcx

WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2x59-2w3w-3ccw

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

CVSS3: 2.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2x59-22p6-6v87

An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x58-77jw-wgpw

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2x57-wp24-3gfm

Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 10
0%
Низкий
около 1 года назад
github логотип
GHSA-2x57-vxvc-jh3v

In the Linux kernel, the following vulnerability has been resolved: bpf: account for current allocated stack depth in widen_imprecise_scalars() The usage pattern for widen_imprecise_scalars() looks as follows: prev_st = find_prev_entry(env, ...); queued_st = push_stack(...); widen_imprecise_scalars(env, prev_st, queued_st); Where prev_st is an ancestor of the queued_st in the explored states tree. This ancestor is not guaranteed to have same allocated stack depth as queued_st. E.g. in the following case: def main(): for i in 1..2: foo(i) // same callsite, differnt param def foo(i): if i == 1: use 128 bytes of stack iterator based loop Here, for a second 'foo' call prev_st->allocated_stack is 128, while queued_st->allocated_stack is much smaller. widen_imprecise_scalars() needs to take this into account and avoid accessing bpf_verifier_state->frame[*]->stack out of bounds.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2x56-wxfv-qqrm

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x55-mg9r-24f7

Magento 2 Community Edition RCE Vulnerability

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x55-cxhq-4m7q

SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x54-j4m3-r6wx

sqla-yaml-fixtures is vulnerable to Code Injection

CVSS3: 7.8
0%
Низкий
около 7 лет назад
github логотип
GHSA-2x54-cv5h-7995

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2x53-xr45-qcv3

SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2x53-x293-3jfh

A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x53-jv7f-c2x5

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x52-8f29-7cjr

Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure

CVSS3: 6.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x4x-xw83-gw6x

Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2x4x-fh63-4wpq

Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2x4x-73fj-7gr8

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2x4w-j73f-g9qq

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2x4w-2j26-p5hx

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the MIDIStreaming endpoint descriptors are filled with the correct information, bNumEmbMIDIJack and bLength are set incorrectly in these descriptors. This does not matter when the numbers of in and out ports are equal, but when they differ the host will receive broken descriptors with uninitialized stack memory leaking into the descriptor for whichever value is smaller. The precise meaning of "in" and "out" in the port counts is not clearly defined and can be confusing. But elsewhere the driver consistently uses this to match the USB meaning of IN and OUT viewed from the host, so that "in" ports send data to the host and "out" ports receive data from it.

CVSS3: 5.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу