Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-22q3-4v32-4m7c

больше 1 года назад

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-22q2-gf4f-hvw6

около 2 месяцев назад

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

EPSS: Низкий
github логотип

GHSA-22px-9px7-pc64

больше 3 лет назад

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

EPSS: Низкий
github логотип

GHSA-22pw-2xmq-86xg

больше 3 лет назад

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

EPSS: Низкий
github логотип

GHSA-22pv-7v9j-hqxp

больше 3 лет назад

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pv-795j-9r7p

больше 2 лет назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pr-vjq7-4qcg

больше 3 лет назад

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22pr-mvmh-vgg5

больше 3 лет назад

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-22pp-q7jc-mc64

больше 3 лет назад

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

EPSS: Средний
github логотип

GHSA-22pp-gfq3-734r

больше 3 лет назад

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22pm-jxcw-xcx5

больше 3 лет назад

There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.

EPSS: Низкий
github логотип

GHSA-22pm-3j5r-cgw3

больше 2 лет назад

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-22ph-w354-vrgv

около 3 лет назад

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22ph-2jjc-cggf

больше 3 лет назад

c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

EPSS: Низкий
github логотип

GHSA-22pg-w2f6-xfjw

около 1 месяца назад

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22pg-r6fg-6256

больше 3 лет назад

Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.

EPSS: Низкий
github логотип

GHSA-22pf-6rh7-89gj

11 месяцев назад

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22pc-rqp3-3hrg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

EPSS: Низкий
github логотип

GHSA-22p9-vg4g-45mc

больше 3 лет назад

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

EPSS: Низкий
github логотип

GHSA-22p9-v5cc-5f4w

больше 3 лет назад

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22q3-4v32-4m7c

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-22q2-gf4f-hvw6

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22px-9px7-pc64

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pw-2xmq-86xg

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pv-7v9j-hqxp

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22pv-795j-9r7p

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22pr-vjq7-4qcg

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pr-mvmh-vgg5

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
23%
Средний
больше 3 лет назад
github логотип
GHSA-22pp-q7jc-mc64

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

13%
Средний
больше 3 лет назад
github логотип
GHSA-22pp-gfq3-734r

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-22pm-jxcw-xcx5

There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pm-3j5r-cgw3

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22ph-w354-vrgv

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-22ph-2jjc-cggf

c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22pg-w2f6-xfjw

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22pg-r6fg-6256

Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pf-6rh7-89gj

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-22pc-rqp3-3hrg

Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22p9-vg4g-45mc

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22p9-v5cc-5f4w

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу