Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2vg5-px79-v62f

3 месяца назад

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2vg5-gq78-m2fx

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

EPSS: Низкий
github логотип

GHSA-2vg5-5q9m-8f9q

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Matt van Andel Custom List Table Example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through 1.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vg5-244r-2cmh

больше 3 лет назад

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vg4-g4gm-pvj7

почти 4 года назад

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-2vg3-8hw9-v322

11 месяцев назад

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vg3-2jpr-xp58

почти 4 года назад

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

EPSS: Низкий
github логотип

GHSA-2vg2-p84m-hhr5

больше 3 лет назад

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vg2-f293-3rc8

больше 3 лет назад

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

EPSS: Низкий
github логотип

GHSA-2vfx-mj86-p92f

почти 4 года назад

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

EPSS: Низкий
github логотип

GHSA-2vfx-8pj2-gpp8

почти 2 года назад

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19477.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2vfx-6mjq-9ccv

больше 3 лет назад

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2vfw-8m4f-jmc8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.

EPSS: Низкий
github логотип

GHSA-2vfv-v6m4-65x6

почти 4 года назад

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

EPSS: Низкий
github логотип

GHSA-2vfq-pq87-ph87

12 месяцев назад

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vfq-7gxj-92hg

больше 1 года назад

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vfp-x8jm-58cj

больше 3 лет назад

Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vfp-rfhc-3mm2

2 месяца назад

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2vfp-cq97-7pq2

больше 3 лет назад

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2417.

EPSS: Низкий
github логотип

GHSA-2vfp-2qpf-jwrq

больше 3 лет назад

A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vg5-px79-v62f

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
0%
Низкий
3 месяца назад
github логотип
GHSA-2vg5-gq78-m2fx

Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vg5-5q9m-8f9q

Cross-Site Request Forgery (CSRF) vulnerability in Matt van Andel Custom List Table Example allows Reflected XSS.This issue affects Custom List Table Example: from n/a through 1.4.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2vg5-244r-2cmh

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vg4-g4gm-pvj7

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vg3-8hw9-v322

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-2vg3-2jpr-xp58

Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vg2-p84m-hhr5

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vg2-f293-3rc8

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfx-mj86-p92f

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

9%
Низкий
почти 4 года назад
github логотип
GHSA-2vfx-8pj2-gpp8

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19477.

CVSS3: 7.8
34%
Средний
почти 2 года назад
github логотип
GHSA-2vfx-6mjq-9ccv

pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfw-8m4f-jmc8

Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfv-v6m4-65x6

Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vfq-pq87-ph87

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2vfq-7gxj-92hg

A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vfp-x8jm-58cj

Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfp-rfhc-3mm2

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2vfp-cq97-7pq2

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2417.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfp-2qpf-jwrq

A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVSS3: 8.8
6%
Низкий
больше 3 лет назад

Уязвимостей на страницу