Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2v77-g93r-76vh

около 1 года назад

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2v77-g7rx-9jjr

больше 3 лет назад

Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Analytics Web General.

EPSS: Низкий
github логотип

GHSA-2v76-ghxq-9xvj

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: driver core: Fix wait_for_device_probe() & deferred_probe_timeout interaction Mounting NFS rootfs was timing out when deferred_probe_timeout was non-zero [1]. This was because ip_auto_config() initcall times out waiting for the network interfaces to show up when deferred_probe_timeout was non-zero. While ip_auto_config() calls wait_for_device_probe() to make sure any currently running deferred probe work or asynchronous probe finishes, that wasn't sufficient to account for devices being deferred until deferred_probe_timeout. Commit 35a672363ab3 ("driver core: Ensure wait_for_device_probe() waits until the deferred_probe_timeout fires") tried to fix that by making sure wait_for_device_probe() waits for deferred_probe_timeout to expire before returning. However, if wait_for_device_probe() is called from the kernel_init() context: - Before deferred_probe_initcall() [2], it causes the boot process to hang due to...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2v76-28wf-qm87

около 2 месяцев назад

An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2v75-jgr3-vhp6

почти 4 года назад

Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2v74-gvxm-8wmq

больше 3 лет назад

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2v74-9vqm-pm8p

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

EPSS: Низкий
github логотип

GHSA-2v73-9rwq-75qc

почти 4 года назад

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

EPSS: Низкий
github логотип

GHSA-2v73-62r7-82cv

почти 4 года назад

SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.

EPSS: Низкий
github логотип

GHSA-2v72-cqvg-78vr

больше 3 лет назад

SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.

EPSS: Низкий
github логотип

GHSA-2v6x-frw8-7r7f

больше 4 лет назад

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v6w-2mr8-f976

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

EPSS: Низкий
github логотип

GHSA-2v6v-q994-xvxx

почти 4 года назад

Privilege escalation in beego

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2v6v-j3q5-hq45

больше 3 лет назад

There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

EPSS: Низкий
github логотип

GHSA-2v6r-jf2g-j5q5

больше 3 лет назад

Cross-site Scripting in Jenkins Rich Text Publisher Plugin

CVSS3: 8
EPSS: Средний
github логотип

GHSA-2v6m-48p8-wjx7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2v6m-44mf-8673

почти 4 года назад

Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.

EPSS: Низкий
github логотип

GHSA-2v6j-q8j6-q6m9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2v6j-6m6r-28qj

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

EPSS: Низкий
github логотип

GHSA-2v6h-6jq5-f6mw

больше 3 лет назад

PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v77-g93r-76vh

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2v77-g7rx-9jjr

Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Analytics Web General.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v76-ghxq-9xvj

In the Linux kernel, the following vulnerability has been resolved: driver core: Fix wait_for_device_probe() & deferred_probe_timeout interaction Mounting NFS rootfs was timing out when deferred_probe_timeout was non-zero [1]. This was because ip_auto_config() initcall times out waiting for the network interfaces to show up when deferred_probe_timeout was non-zero. While ip_auto_config() calls wait_for_device_probe() to make sure any currently running deferred probe work or asynchronous probe finishes, that wasn't sufficient to account for devices being deferred until deferred_probe_timeout. Commit 35a672363ab3 ("driver core: Ensure wait_for_device_probe() waits until the deferred_probe_timeout fires") tried to fix that by making sure wait_for_device_probe() waits for deferred_probe_timeout to expire before returning. However, if wait_for_device_probe() is called from the kernel_init() context: - Before deferred_probe_initcall() [2], it causes the boot process to hang due to...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2v76-28wf-qm87

An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2v75-jgr3-vhp6

Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2v74-gvxm-8wmq

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

CVSS3: 8.8
34%
Средний
больше 3 лет назад
github логотип
GHSA-2v74-9vqm-pm8p

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

0%
Низкий
4 месяца назад
github логотип
GHSA-2v73-9rwq-75qc

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2v73-62r7-82cv

SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2v72-cqvg-78vr

SecurityAgent in Apple OS X before 10.10 does not ensure that a Kerberos ticket is in the cache for the correct user, which allows local users to gain privileges in opportunistic circumstances by leveraging a Fast User Switching login.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v6x-frw8-7r7f

Duplicate Advisory: k8s.io/kube-state-metrics Exposure of Sensitive Information

CVSS3: 6.5
больше 4 лет назад
github логотип
GHSA-2v6w-2mr8-f976

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2v6v-q994-xvxx

Privilege escalation in beego

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2v6v-j3q5-hq45

There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v6r-jf2g-j5q5

Cross-site Scripting in Jenkins Rich Text Publisher Plugin

CVSS3: 8
14%
Средний
больше 3 лет назад
github логотип
GHSA-2v6m-48p8-wjx7

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v6m-44mf-8673

Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2v6j-q8j6-q6m9

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVSS3: 6.1
22%
Средний
больше 3 лет назад
github логотип
GHSA-2v6j-6m6r-28qj

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v6h-6jq5-f6mw

PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу