Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2vm7-46v4-pr85

больше 3 лет назад

An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vm6-973m-fwf6

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.

EPSS: Низкий
github логотип

GHSA-2vm6-24x2-fw9m

около 4 лет назад

There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vm5-6gc7-pcvr

больше 3 лет назад

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vm4-jjww-7x6m

26 дней назад

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vm4-g44x-w548

больше 3 лет назад

Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vjx-vmx2-m3h4

больше 3 лет назад

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vjx-rcxr-r2p5

больше 3 лет назад

Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vjx-96pr-9r8r

почти 4 года назад

A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.

EPSS: Низкий
github логотип

GHSA-2vjx-859r-qm27

8 дней назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not currently doing this, that would lead to a memory leak. So, fix it.

EPSS: Низкий
github логотип

GHSA-2vjw-w57f-jmf6

4 месяца назад

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vjv-62j5-c7h3

больше 2 лет назад

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vjv-2jwr-w8hr

6 месяцев назад

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vjr-qrh8-pp9c

7 месяцев назад

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vjr-cvf4-9474

больше 3 лет назад

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, allowing attackers to inject SQL commands into the URL.

EPSS: Низкий
github логотип

GHSA-2vjr-3244-hj86

больше 3 лет назад

Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-2vjr-23vj-3cq8

почти 4 года назад

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.

EPSS: Низкий
github логотип

GHSA-2vjq-hg5w-5gm7

больше 1 года назад

OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vjq-g46g-w383

почти 4 года назад

Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.

EPSS: Средний
github логотип

GHSA-2vjp-w357-hqrg

больше 3 лет назад

Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vm7-46v4-pr85

An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vm6-973m-fwf6

Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vm6-24x2-fw9m

There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2vm5-6gc7-pcvr

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vm4-jjww-7x6m

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files.

CVSS3: 9.8
0%
Низкий
26 дней назад
github логотип
GHSA-2vm4-g44x-w548

Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vjx-vmx2-m3h4

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security Note 2234226.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vjx-rcxr-r2p5

Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vjx-96pr-9r8r

A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vjx-859r-qm27

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix kvm_device leak in kvm_ipi_destroy() In kvm_ioctl_create_device(), kvm_device has allocated memory, kvm_device->destroy() seems to be supposed to free its kvm_device struct, but kvm_ipi_destroy() is not currently doing this, that would lead to a memory leak. So, fix it.

0%
Низкий
8 дней назад
github логотип
GHSA-2vjw-w57f-jmf6

Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2vjv-62j5-c7h3

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vjv-2jwr-w8hr

An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

CVSS3: 5.4
5%
Низкий
6 месяцев назад
github логотип
GHSA-2vjr-qrh8-pp9c

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2vjr-cvf4-9474

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, allowing attackers to inject SQL commands into the URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vjr-3244-hj86

Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vjr-23vj-3cq8

Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2vjq-hg5w-5gm7

OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vjq-g46g-w383

Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.

26%
Средний
почти 4 года назад
github логотип
GHSA-2vjp-w357-hqrg

Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

56%
Средний
больше 3 лет назад

Уязвимостей на страницу